Impact
The flaw is a heap-based buffer overflow in GIMP's HDR file parser caused by an unchecked length field. An attacker can supply a malicious HDR file that causes the program to copy data past the bounds of a heap buffer, allowing the attacker to execute arbitrary code in the context of the current GIMP process and thereby gain full control of the host system.
Affected Systems
The vulnerability affects all affected installations of GIMP that use the HDR file parsing routine; no specific version constraints are listed in the advisory. The vendor supplying the affected product is GIMP.
Risk and Exploitability
The CVSS score of 7.8 indicates a high potential impact. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, so current exploitation probability is uncertain. Exploitation requires user interaction—an attacker must trick a user into opening a malicious HDR file or visiting a page that triggers the file open dialog—making the attack vector rely on social engineering or malicious content delivery. Once triggered, the heap overflow leads to remote code execution with the privileges of the GIMP process, potentially allowing arbitrary system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA