REDHAT-BUG-2522072: Medium severity GIMP GIMP file-pix (ESM) plugin vulnerability
A flaw was found in the file-pix (ESM) plugin in GIMP, affecting versions 3.0.0 and newer. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.
Affected Software
Event History
Frequently Asked Questions
Which installations are in scope for triage?
GIMP installations using the file-pix (ESM) plugin are affected if they are version 3.0.0 or newer.
What must occur for an attacker to trigger the flaw?
The file-pix (ESM) plugin must process a specially crafted PIX image file. The reported outcomes are stack exhaustion causing denial of service and limited disclosure of stack memory contents into an intermediate file.