Impact
GIMP contains a stack-based buffer overflow in the TIFF image parser that allows an attacker to execute arbitrary code on a system running the vulnerable application. The flaw is caused by the failure to validate the length of user-supplied data before copying it into a stack buffer. An attacker who convinces the user to open a malicious TIFF file can trigger the overflow and run code with the same privileges as the GIMP process. The vulnerability is classified as CWE-121, a classic stack buffer overflow.
Affected Systems
All installations of GIMP that have not been updated to versions containing the fix from the commit identified in the advisory are affected. No specific version range is listed, so any GIMP release held in a system inventory should be checked against the latest patch. Users who maintain older GIMP instances or use unsupported versions are at higher risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, and the vulnerability requires user interaction, meaning attackers need either a malicious webpage or a crafted file to lure a user into opening a TIFF image. The EPSS score of < 1% suggests a low but nonzero probability of exploitation, while the existence of a patch on the vendor’s repository and an advisory by ZeroDay Initiative implies that attackers are aware of the flaw. The vulnerability is not listed in CISA KEV, though that does not preclude exploitation. A remote attacker can achieve code execution in the context of the current user by exploiting this flaw under the conditions described.
OpenCVE Enrichment
Debian DSA