Impact
The vulnerability is a heap out‑of‑bounds read in GIMP’s XWD loader caused by independent validation of image width and bytes‑per‑line, allowing the plugin to read beyond the allocated buffer. This can crash the application, causing a denial of service, or expose portions of heap memory in the produced image, leading to a limited information disclosure. The weakness is identified as CWE‑125.
Affected Systems
This flaw affects the GIMP file‑xwd plugin on Red Hat Enterprise Linux releases 6, 7, 8, and 9, as listed by the vendor. No specific patched versions are noted, so the vulnerability is presumed present in the versions shipped with those RHEL releases.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, and the EPSS score is unavailable, suggesting no known widespread exploitation. The flaw is not listed in CISA’s KEV catalog. Exploitation requires the attacker to deliver a specially crafted XWD file to a user who opens it with GIMP; thus the attack vector is local or social‑engineering based rather than remote network exposure. The potential impact is a service disruption or subtle information leak, but the risk is limited to environments where GIMP processes untrusted XWD files.
OpenCVE Enrichment