PT-2026-81853 · Gimp · Gimp
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
GIMP (affected versions not specified)
Description
A flaw in the file-xwd plugin occurs when processing specially crafted XWD image files. The plugin validates image width and bytes-per-line parameters independently instead of ensuring their combined values align with the allocated buffer size. This improper bounds checking in the
load xwd f2 d1 b1() and load xwd f1 d24 b1() functions leads to a heap out-of-bounds read, which is a condition where the program reads data past the end of the intended memory buffer. This can result in an application crash causing a denial of service or a limited information disclosure of heap memory contents into the resulting image.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gimp