Impact
GIMP’s SGI file parser contains an unchecked integer that can overflow before memory is written. Exploiting this flaw allows a malicious actor to execute arbitrary code in the context of the running GIMP process. The vulnerability is classified as CWE‑190, an improper input validation weakness that can lead to uncontrolled memory access.
Affected Systems
The only identified product impacted is GIMP. No specific version range is listed in the CNA data, so any installation of the image editor that has not applied the relevant patch should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while an EPSS value is unavailable and the vulnerability is not listed in the CISA KEV catalogue. Attackers must supply a crafted SGI file or lure the user to a malicious page that triggers the parser; user interaction is required. If successful, the attacker can run code with the privileges of the user running GIMP, potentially compromising the host system.
OpenCVE Enrichment