Impact
A flaw exists in GIMP’s handling of XWD files where insufficient validation of user-supplied data allows a write past the end of an allocated buffer. This out‑of‑bounds write can overwrite control data in the process, giving an attacker the ability to execute arbitrary code with the same privileges as the GIMP process. The vulnerability is limited to the XWD file parser and does not involve other file formats or components of the application.
Affected Systems
GIMP version 3.0.6 is the specifically identified affected build; other versions that still use the same XWD parsing code may also be impacted, but no additional products or vendors are listed as affected.
Risk and Exploitability
The CVSS base score of 7.3 indicates a high severity, while the EPSS score of 5% suggests that exploitation is moderately likely in the present environment. The vulnerability is not listed in CISA’s KEV catalog, reflecting that no publicly known exploits are currently documented. Exploitation requires user interaction, typically by opening a crafted XWD file or loading it through a web page that references the file; the attacker must thus entice or trick the user into executing the file. Given the remote code execution potential and the moderate EPSS probability, administrators should prioritize addressing this flaw quickly.
OpenCVE Enrichment
Debian DLA
Debian DSA