CVE-2022-32990: Medium severity gimp vulnerability
Published Jun 24, 2022
·Updated
An issue in gimplayerinvalidateboundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS).
Affected Software
2 affected componentsFixes available
debian/gimp<=2.10.22-4+deb11u2, <=2.10.22-4+deb11u1
2.10.34-1+deb12u22.10.34-1+deb12u13.0.0~RC2-1
GIMP=2.10.30
Remediation
Patch Available
Event History
Jun 24, 2022
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
Description
Jan 12, 2024
Data Sourced
via Launchpad·04:01 PM
Description
Jan 16, 2025
Data Sourced
via Ubuntu·07:12 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-32990.
2
What is the severity of CVE-2022-32990?
The severity of CVE-2022-32990 is medium with a severity value of 5.5.
3
What software is affected by CVE-2022-32990?
GNOME GIMP 2.10.30 is affected by CVE-2022-32990.
4
How can an attacker exploit CVE-2022-32990?
An attacker can exploit CVE-2022-32990 by triggering an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS).
5
Is there a fix available for CVE-2022-32990?
You can refer to the GitLab issue for updates and possible fixes for CVE-2022-32990: https://gitlab.gnome.org/GNOME/gimp/-/issues/8230