CVE-2025-48797: Gimp: multiple heap buffer overflows in tga parser
A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.
Other sources
GIMP prior to version 3.0.0 is vulnerable to two buffer over-reads and one heap-based buffer overflow in its TGA parser. A malicious TGA file may attempt to abuse these vulnerabilities to achieve code execution.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GIMPto a version that resolves this vulnerability.Fixed in 3.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48797?
CVE-2025-48797 is considered a high severity vulnerability due to the potential for heap buffer overflow leading to crashes.
How do I fix CVE-2025-48797?
To fix CVE-2025-48797, update GIMP to the latest version beyond 3.0.0 to mitigate the vulnerability.
Which versions of GIMP are affected by CVE-2025-48797?
CVE-2025-48797 affects GIMP versions up to and including 3.0.0.
What types of attacks can exploit CVE-2025-48797?
CVE-2025-48797 can be exploited by specially crafted TGA image files, which can lead to serious memory errors.
What are the consequences of exploiting CVE-2025-48797?
Exploiting CVE-2025-48797 may result in application crashes and potentially execution of arbitrary code due to heap buffer overflow.