Impact
A flaw in the GIMP Paint Shop Pro image parser results in a heap buffer overflow (CWE-122). When GIMP opens low‑bit‑depth PSP files it incorrectly calculates buffer sizes, causing adjacent memory to be overwritten. An attacker who entices a user to open a specially crafted file can therefore achieve arbitrary code execution or cause a denial of service on the victim machine.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux releases 6, 7, 8, and 9, because GIMP is delivered as a package in those distributions. The CNA has not specified which GIMP versions are impacted, so the exact version numbers bundled with each distribution are unknown.
Risk and Exploitability
The CVSS score of 7.3 indicates moderate to high severity, while the EPSS score of < 1% shows a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attacking requires a user to open a malicious PSP file, which is a user‑based, social‑engineering vector that can lead to remote code execution or system crash.
OpenCVE Enrichment