Impact
A flaw in GIMP’s Seattle FilmWorks plugin allows an attacker to create a specially crafted SFW image file that causes the plugin to allocate a variable‑length array on the stack without performing integer overflow checks, resulting in an unbounded stack allocation. The memory corruption triggers an application crash, which is a denial of service of the GIMP process. No broader confidentiality or integrity impacts are described in the CVE statement.
Affected Systems
The vulnerability affects GIMP as supplied by GNOME and the Seattle FilmWorks plugin on Red Hat Enterprise Linux 6, 7, 8, and 9. Red Hat provides the packaged GIMP installation on these operating systems, so users running the default GIMP package with the plugin are potentially impacted.
Risk and Exploitability
The CVSS score of 5.5 places the flaw in the medium severity range. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or remote and requires an attacker to get a user to open a malicious SFW file, for example via email or compromised web sites. No elevated privileges are required to exploit the flaw, and the impact is confined to the GIMP process. Because a workaround is available, the risk can be mitigated until an official patch is released.
OpenCVE Enrichment