REDHAT-BUG-2368558: Buffer Overflow
Published May 26, 2025
·Updated
GIMP prior to version 3.0.0 is vulnerable to two buffer over-reads and one heap-based buffer overflow in its TGA parser. A malicious TGA file may attempt to abuse these vulnerabilities to achieve code execution.
Affected Software
1 affected component
Gnome GIMP<3.0.0
Event History
May 26, 2025
Data Sourced
via Red Hat·10:52 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2368558?
The severity of REDHAT-BUG-2368558 is high due to the potential for code execution from a malicious TGA file.
2
How do I fix REDHAT-BUG-2368558?
To fix REDHAT-BUG-2368558, upgrade GIMP to version 3.0.0 or later.
3
What types of vulnerabilities are associated with REDHAT-BUG-2368558?
REDHAT-BUG-2368558 is associated with buffer over-reads and a heap-based buffer overflow in the TGA parser.
4
Who is affected by REDHAT-BUG-2368558?
Users of GIMP versions prior to 3.0.0 are affected by REDHAT-BUG-2368558.
5
What is the potential impact of exploiting REDHAT-BUG-2368558?
Exploiting REDHAT-BUG-2368558 may allow an attacker to execute arbitrary code on the user's system.