Impact
A heap-based buffer overflow exists in GIMP’s Hot color filter plug‑in. The plugin allocates a pixel buffer using 32‑bit arithmetic that multiplies width by height. If an image’s dimensions overflow this calculation, the allocated size is smaller than the true image size. Subsequent filter processing writes beyond the buffer, corrupting heap memory. This flaw can enable an attacker who supplies an oversized image to overwrite critical control data or inject malicious code.
Affected Systems
The GIMP package that ships with Red Hat Enterprise Linux versions 6 through 10 contains the vulnerable Hot filter plug‑in. The vulnerability applies to all RHEL releases that provide GIMP, regardless of how images are obtained. Any system running these distributions and using GIMP is potentially affected.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that it has not yet been widely exploited. The likely attack vector is local use of untrusted large images: an attacker crafts an oversized image, opens it in GIMP, and triggers the overflow. Successful exploitation could lead to heap corruption and potentially arbitrary code execution or a crash.
OpenCVE Enrichment