Impact
A signed integer overflow in the GIMP file-fli plugin causes a crash when processing a specially crafted FLI image. The overflow occurs during memory allocation when the image’s width multiplied by its height exceeds the maximum signed integer value. This leads to application termination and results in a denial of service for the user who opens the file.
Affected Systems
The flaw exists in GIMP packages distributed with Red Hat Enterprise Linux 6 through 9. Any system that has an affected GIMP installation on these RHEL releases can become vulnerable if it opens an untrusted FLI file. Systems using different operating systems or newer versions of GIMP that are not shipped with RHEL are not listed as affected by this CVE.
Risk and Exploitability
The CVSS score of 5.5 reflects moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a malicious FLI file and persuade the user to open it, implicating a user‑interaction attack vector. Because the vector relies on crafted file handling rather than remote network access, the likelihood of widespread exploitation is low, but the impact is a local denial of service that can disrupt user workflows.
OpenCVE Enrichment
Debian DSA