CVE-2025-48796: Gimp: stack-based buffer overflows in file-ico
A flaw was found in GIMP. The GIMP aniloadimage() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file to trigger arbitrary code execution.
Other sources
GIMP prior to version 2.99.16 is vulnerable to a stack-based buffer overflow in the aniloadimage() function. A malicious ANI file may achieve arbitrary code execution.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GIMPto a version that resolves this vulnerability.Fixed in 2.99.16
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48796?
CVE-2025-48796 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2025-48796?
To mitigate CVE-2025-48796, users should upgrade GIMP to version 2.99.16 or later.
What is the impact of CVE-2025-48796 on GIMP?
The impact of CVE-2025-48796 allows a malicious ANI file to exploit a stack-based buffer overflow, leading to potential arbitrary code execution.
Is GIMP 2.99.16 affected by CVE-2025-48796?
No, GIMP version 2.99.16 and later are not affected by CVE-2025-48796.
What versions of GIMP are vulnerable to CVE-2025-48796?
GIMP versions prior to 2.99.16 are vulnerable to CVE-2025-48796.