PT-2026-67639 · Gimp · Gimp
CVE-2026-42169
·
Published
2026-08-04
·
Updated
2026-08-20
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GIMP (affected versions not specified)
Description
A heap-buffer-overflow exists in the APNG (Animated PNG) file loader, occurring when the
fcTL width exceeds the IHDR width, which causes pixel data to be written beyond the heap allocation boundary. Furthermore, a heap-based buffer overflow is present in the DDS plug-in caused by a BPP (Bits Per Pixel) mismatch within the load layer() function. These issues can be triggered by opening a specially crafted image file, which may lead to arbitrary code execution.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gimp