Impact
A flaw in GIMP’s Seattle Filmworks file loader writes a user‑controlled length into an undersized buffer during fread, causing a heap overflow. This memory corruption can lead to the execution of attacker‑controlled code or a denial of service if the buffer is overwritten with malicious data.
Affected Systems
The vulnerability affects the GIMP image manipulation program shipped with Red Hat Enterprise Linux 6, 7, 8 and 9. Exact patch levels are not specified, but any installation containing the vulnerable GIMP version is at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate‑to‑high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a user to open a specially crafted .sfw file, so the attack vector is local and interactive. Successful exploitation could allow an attacker to inject arbitrary code or crash the application.
OpenCVE Enrichment