Impact
A flaw exists in GIMP’s file format plugins, specifically those handling PSD and PAA images. The vulnerability is a memory corruption bug (CWE‑787) that can be triggered when a user opens a specially crafted image file. The resulting unexpected application behaviour could allow an attacker to execute arbitrary code or cause a crash, depending on the circumstances, without requiring additional user actions beyond opening the file.
Affected Systems
The affected product is GIMP, which is available on Red Hat Enterprise Linux versions 6 through 9. Any installation of GIMP on those operating systems is potentially vulnerable to the described issue.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity attack with significant potential impact. The EPSS score is not available, but the lack of a KEV listing suggests no widespread exploitation has been observed yet. Attackers are likely to use social engineering, sending malicious image files to trick users into opening them. The primary attack vector is local file execution, though remote delivery via phishing is possible. Until a vendor fix is released, the risk remains significant for users who handle untrusted image files.
OpenCVE Enrichment