REDHAT-BUG-2368559: Buffer Overflow
Published May 26, 2025
·Updated
GIMP prior to version 2.99.16 is vulnerable to a stack-based buffer overflow in the aniloadimage() function. A malicious ANI file may achieve arbitrary code execution.
Affected Software
1 affected component
GIMP<2.99.16
Event History
May 26, 2025
Data Sourced
via Red Hat·10:52 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2368559?
The severity of REDHAT-BUG-2368559 is critical due to the potential for arbitrary code execution.
2
How do I fix REDHAT-BUG-2368559?
To fix REDHAT-BUG-2368559, upgrade GIMP to version 2.99.16 or later.
3
What part of GIMP is affected by REDHAT-BUG-2368559?
The ani_load_image() function in GIMP versions prior to 2.99.16 is affected by REDHAT-BUG-2368559.
4
What type of vulnerability is REDHAT-BUG-2368559?
REDHAT-BUG-2368559 is a stack-based buffer overflow vulnerability.
5
Can a malicious ANI file exploit REDHAT-BUG-2368559?
Yes, a malicious ANI file can exploit REDHAT-BUG-2368559 to achieve arbitrary code execution.