Impact
A flaw in the GIMP GIMPressionist plugin allows a specially crafted preset file to bypass vector index validation and write beyond the bounds of fixed-size arrays. This out‑of‑bounds write corrupts memory and can lead to a program crash or the execution of arbitrary code. The vulnerability directly compromises memory integrity and, if exploited, grants attackers the ability to take control of the system in which the compromised GIMP instance runs.
Affected Systems
The vulnerability affects GIMP installations running on Red Hat Enterprise Linux releases 6 through 10. Any system that has GIMP installed and that loads GIMPressionist preset files from untrusted sources is potentially affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity impact. The EPSS score is unavailable, but the lack of listing in the CISA KEV catalog suggests no widespread exploitation has been observed to date. The likely attack vector involves an attacker convincing a user to load a malicious preset file, which can be delivered through social engineering, phishing, or malicious websites. While the exploit requires local file access or user interaction, the resulting memory corruption could lead to arbitrary code execution if the attack succeeds.
OpenCVE Enrichment