Gimp before 2.8.22 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a similar issue to CVE-2007-2237.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gimp | Jul 30, 2024 | Jun 8, 2007 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 7, 2022 |
| Suse | — | Upgrade gimp-develUpgrade gimp-langUpgrade gimp-plugins-pythonUpgrade gimp-plugin-aaUpgrade libgimpui-2_0-0Upgrade libgimp-2_0-0Upgrade gimp | Apr 26, 2018 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub