Impact
A flaw in GIMP’s Paint Shop Pro file parser results in a heap buffer overflow (CWE‑122). When the program processes low‑bit‑depth PSP images it incorrectly calculates buffer sizes, leading to an overwrite of adjacent memory. This memory corruption can enable an attacker who tricks a user into opening a malicious PSP file to achieve arbitrary code execution or cause a denial of service on the victim machine.
Affected Systems
The vulnerability affects the Red Hat Enterprise Linux releases 6, 7, 8, and 9, because GIMP is distributed as a package in those operating systems. The CNA does not provide explicit GIMP version information, so the specific versions of GIMP bundled with those distributions are unknown.
Risk and Exploitability
The CVSS score of 7.3 indicates moderate to high severity, while the EPSS score of < 1% shows a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is user‑based; a remote attacker must entice a user to open a malicious PSP file, a form of social engineering that can result in arbitrary code execution or a system crash.
OpenCVE Enrichment