Impact
A heap-based buffer overflow occurs in the PCX export plug‑in of GIMP. When the image width and height are extremely large, the plug‑in calculates the buffer size by multiplying 32‑bit width and height values. Because this multiplication overflows, an incorrectly sized buffer is allocated, and subsequent GEGL operations use the true image size. It is inferred that the overflow may allow an attacker to write beyond the allocated memory, potentially leading to arbitrary code execution, although the source text does not explicitly state this outcome. This issue is classified as CWE‑119.
Affected Systems
The flaw affects Red Hat Enterprise Linux distributions 6 through 10, as the vulnerable GIMP package is available on these platforms. It is inferred that any system that runs GIMP and exports large images to the PCX format would be susceptible, though this specific claim is not directly stated in the source information. The issue is not limited to a particular release of the operating system, but rather to the presence of the vulnerable GIMP plug‑in in the system’s package set.
Risk and Exploitability
The CVSS base score of 6.3 indicates a moderate severity. The EPSS score is not reported, and the vulnerability is not yet listed in CISA’s KEV catalog, suggesting that widespread exploitation may not yet be observed. The attack requires that an attacker provide a crafted image that an ordinary user or process opens and then asks GIMP to export as PCX. It is inferred that a skilled attacker might exploit the exposed memory area, potentially achieving privilege escalation on the host system, though the source does not explicitly confirm this outcome.
OpenCVE Enrichment