Impact
A heap-based buffer overflow is present in GIMP’s Paint Shop Pro file loader. When a compressed selection channel is processed, the allocated buffer is smaller than the decompressed data, allowing a remote attacker to craft a malicious PSP file that can trigger the overflow. If the file is opened, the overflow can lead to a program crash or arbitrary code execution on the host system. The vulnerability is a classic example of CWE-787, where insufficient bounds checking on reference allocations occurs.
Affected Systems
The flaw affects GIMP running on Red Hat Enterprise Linux releases 6 through 9, as disclosed by Red Hat. The impact is limited to installations of GIMP on these platforms; users of other operating systems are not directly affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity infection vector. The EPSS score is < 1%, indicating a very low, yet nonzero, exploitation probability, and the issue is not listed in CISA’s KEV catalogue, but the vulnerability can be triggered by a malicious PSP file delivered to a user. A remote attacker need only entice a victim to open the file, making the risk significant for environments where GIMP is used to process external artwork. Without a patch, exploitation remains feasible.
OpenCVE Enrichment