rpm package
almalinux/gimp-libs
pkg:rpm/almalinux/gimp-libs
Vulnerabilities (38)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-42169 | Hig | 7.3 | < 2:3.0.4-4.el9_8.9 | 2:3.0.4-4.el9_8.9 | Aug 4, 2026 | A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in | |
| CVE-2026-66759 | Hig | 7.1 | < 2:3.0.4-4.el9_8.9 | 2:3.0.4-4.el9_8.9 | Jul 27, 2026 | A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, | |
| CVE-2026-66758 | Hig | 7.8 | < 2:3.0.4-4.el9_8.9 | 2:3.0.4-4.el9_8.9 | Jul 27, 2026 | A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resu | |
| CVE-2026-58384 | Hig | 7.3 | < 2:3.0.4-4.el9_8.7 | 2:3.0.4-4.el9_8.7 | Jul 7, 2026 | A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial | |
| CVE-2026-58380 | Hig | 7.3 | < 2:3.0.4-4.el9_8.7 | 2:3.0.4-4.el9_8.7 | Jul 6, 2026 | A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to me | |
| CVE-2026-58379 | Hig | 7.3 | < 2:3.0.4-4.el9_8.5 | 2:3.0.4-4.el9_8.5 | Jul 3, 2026 | A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerabilit | |
| CVE-2026-4154 | Hig | 7.8 | < 2:3.0.4-1.el9_7.5 | 2:3.0.4-1.el9_7.5 | Apr 11, 2026 | GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious | |
| CVE-2026-4153 | Hig | 7.8 | < 2:3.0.4-1.el9_7.5 | 2:3.0.4-1.el9_7.5 | Apr 11, 2026 | GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | |
| CVE-2026-4152 | Hig | 7.8 | < 2:3.0.4-1.el9_7.5 | 2:3.0.4-1.el9_7.5 | Apr 11, 2026 | GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | |
| CVE-2026-4151 | Hig | 7.8 | < 2:3.0.4-1.el9_7.5 | 2:3.0.4-1.el9_7.5 | Apr 11, 2026 | GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious | |
| CVE-2026-4150 | Hig | 7.8 | < 2:3.0.4-1.el9_7.5 | 2:3.0.4-1.el9_7.5 | Apr 11, 2026 | GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious | |
| CVE-2026-4887 | Med | 6.1 | < 2:3.0.4-1.el9_7.5 | 2:3.0.4-1.el9_7.5 | Mar 26, 2026 | A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosu | |
| CVE-2026-2048 | Hig | 7.8 | < 2:3.0.4-1.el9_7.4 | 2:3.0.4-1.el9_7.4 | Feb 20, 2026 | GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malici | |
| CVE-2026-2047 | Hig | 7.8 | < 2:3.0.4-1.el9_7.4 | 2:3.0.4-1.el9_7.4 | Feb 20, 2026 | GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit | |
| CVE-2026-2045 | Hig | 7.3 | < 2:3.0.4-1.el9_7.4 | 2:3.0.4-1.el9_7.4 | Feb 20, 2026 | GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malici | |
| CVE-2026-2044 | Hig | 8.8 | < 2:3.0.4-1.el9_7.4 | 2:3.0.4-1.el9_7.4 | Feb 20, 2026 | GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malic | |
| CVE-2026-0797 | Hig | 8.8 | < 2:3.0.4-1.el9_7.4 | 2:3.0.4-1.el9_7.4 | Feb 20, 2026 | GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | |
| CVE-2025-15059 | Hig | 7.8 | < 2:3.0.4-1.el9_7.3 | 2:3.0.4-1.el9_7.3 | Jan 23, 2026 | GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | |
| CVE-2025-14425 | Hig | 7.8 | < 2:3.0.4-1.el9_7.2 | 2:3.0.4-1.el9_7.2 | Dec 23, 2025 | GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | |
| CVE-2025-14424 | Hig | 7.8 | < 2:3.0.4-1.el9_7.2 | 2:3.0.4-1.el9_7.2 | Dec 23, 2025 | GIMP XCF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious p |
- affected < 2:3.0.4-4.el9_8.9fixed 2:3.0.4-4.el9_8.9
A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in
- affected < 2:3.0.4-4.el9_8.9fixed 2:3.0.4-4.el9_8.9
A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource,
- affected < 2:3.0.4-4.el9_8.9fixed 2:3.0.4-4.el9_8.9
A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resu
- affected < 2:3.0.4-4.el9_8.7fixed 2:3.0.4-4.el9_8.7
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial
- affected < 2:3.0.4-4.el9_8.7fixed 2:3.0.4-4.el9_8.7
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to me
- affected < 2:3.0.4-4.el9_8.5fixed 2:3.0.4-4.el9_8.5
A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerabilit
- affected < 2:3.0.4-1.el9_7.5fixed 2:3.0.4-1.el9_7.5
GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious
- affected < 2:3.0.4-1.el9_7.5fixed 2:3.0.4-1.el9_7.5
GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- affected < 2:3.0.4-1.el9_7.5fixed 2:3.0.4-1.el9_7.5
GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- affected < 2:3.0.4-1.el9_7.5fixed 2:3.0.4-1.el9_7.5
GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious
- affected < 2:3.0.4-1.el9_7.5fixed 2:3.0.4-1.el9_7.5
GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious
- affected < 2:3.0.4-1.el9_7.5fixed 2:3.0.4-1.el9_7.5
A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosu
- affected < 2:3.0.4-1.el9_7.4fixed 2:3.0.4-1.el9_7.4
GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malici
- affected < 2:3.0.4-1.el9_7.4fixed 2:3.0.4-1.el9_7.4
GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit
- affected < 2:3.0.4-1.el9_7.4fixed 2:3.0.4-1.el9_7.4
GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malici
- affected < 2:3.0.4-1.el9_7.4fixed 2:3.0.4-1.el9_7.4
GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malic
- affected < 2:3.0.4-1.el9_7.4fixed 2:3.0.4-1.el9_7.4
GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- affected < 2:3.0.4-1.el9_7.3fixed 2:3.0.4-1.el9_7.3
GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- affected < 2:3.0.4-1.el9_7.2fixed 2:3.0.4-1.el9_7.2
GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- affected < 2:3.0.4-1.el9_7.2fixed 2:3.0.4-1.el9_7.2
GIMP XCF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious p
Page 1 of 2