ZDI-CAN-29403: ZDI-26-457: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18304.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29403?
ZDI-CAN-29403 has been assigned a CVSS rating of 7.8, indicating a high severity level.
How do I fix ZDI-CAN-29403?
To fix ZDI-CAN-29403, update GIMP to the latest version that addresses this vulnerability.
What causes the vulnerability ZDI-CAN-29403?
ZDI-CAN-29403 is caused by an integer overflow in the TIF file parsing of GIMP.
Can ZDI-CAN-29403 be exploited remotely?
Yes, ZDI-CAN-29403 can be exploited remotely if a user opens a malicious TIF file or visits a compromised page.
What are the potential impacts of ZDI-CAN-29403?
The potential impact of ZDI-CAN-29403 includes arbitrary code execution on affected installations of GIMP.