Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gimp | Aug 30, 2017 | Jul 12, 2016 |
| Debian | — | Upgrade gimp | Jul 4, 2016 | Jul 1, 2016 |
| Freebsd | — | Upgrade gimp-app | Dec 10, 2025 | Jul 19, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade gimp-helpUpgrade gimpUpgrade gimp-libs | Nov 30, 2017 | Jul 12, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade gimp-libsUpgrade gimp | Dec 4, 2019 | Jul 12, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade gimpUpgrade gimp-libs | Sep 25, 2019 | Jul 12, 2016 |
| Oracle Solaris | — | Upgrade image/editor/gimp to version 2.6.10-0.175.3.16.0.1.0 on Solaris 11.3 | May 29, 2017 | Jul 12, 2016 |
| Oracle_linux | — | Upgrade gimp-devel-toolsUpgrade gimp-help-esUpgrade gimp-libsUpgrade gimp-help-ruUpgrade gimp-help-nlUpgrade gimp-help-slUpgrade gimp-help-deUpgrade gimp-help-jaUpgrade gimp-help-pt_BRUpgrade gimp-help-svUpgrade gimp-help-en_GBUpgrade gimp-help-daUpgrade gimp-help-frUpgrade gimpUpgrade gimp-help-itUpgrade gimp-help-caUpgrade gimp-develUpgrade gimp-help-zh_CNUpgrade gimp-helpUpgrade gimp-help-koUpgrade gimp-help-nnUpgrade gimp-help-el | Nov 9, 2016 | Jun 20, 2016 |
| Redhat_linux | — | Upgrade gimp-help-nnUpgrade gimp-help-koUpgrade gimp-help-en_GBUpgrade gimp-help-caUpgrade gimp-help-zh_CNNo solution existsUpgrade gimp-help-itUpgrade gimp-helpUpgrade gimp-help-pt_BRUpgrade gimp-help-ruUpgrade gimp-help-deUpgrade gimp-help-frUpgrade gimp-help-esUpgrade gimp-debuginfoUpgrade gimp-develUpgrade gimp-help-daUpgrade gimp-libsUpgrade gimp-help-slUpgrade gimp-help-nlUpgrade gimpUpgrade gimp-help-jaUpgrade gimp-help-elUpgrade gimp-devel-toolsUpgrade gimp-help-sv | Nov 4, 2016 | Jul 12, 2016 |
| Suse | — | Upgrade gimp-plugins-pythonUpgrade libgimp-2_0-0Upgrade gimp-langUpgrade libgimpui-2_0-0Upgrade gimpUpgrade gimp-plugin-aaUpgrade gimp-devel | Jul 26, 2016 | Jul 12, 2016 |
| Ubuntu | — | Upgrade gimp | Jul 5, 2016 | Jul 5, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub