PT-2023-7278 · Gimp+7 · Gimp+7

Michael Randrianantenaina

·

Publicado

2023-11-14

·

Atualizado

2025-08-14

·

CVE-2023-44443

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GIMP (affected versions not specified)
Description The issue is related to an integer overflow in the parsing of PSP files, which can be exploited by remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required, where the target must visit a malicious page or open a malicious file. The problem stems from the lack of proper validation of user-supplied data, leading to an integer overflow before writing to memory. This allows an attacker to execute code in the context of the current process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2024:0675
ALSA-2025:0746
ALSA-2025:3617
ALSA-2025:7417
BDU:2023-08306
CESA-2025_0746
CVE-2023-44443
DSA-5564-1
INFSA-2024_0675
INFSA-2025_0746
INFSA-2025_3617
INFSA-2025_7417
MGASA-2023-0346
OPENSUSE-SU-2024:14534-1
RHSA-2024:0675
RHSA-2024:0702
RHSA-2024:0716
RHSA-2024_0675
RHSA-2025:0746
RHSA-2025:3617
RHSA-2025:3629
RHSA-2025:7417
RHSA-2025_0746
RHSA-2025_3617
RHSA-2025_7417
RLSA-2024:0675
RLSA-2025:0746
SUSE-SU-2023:4692-1
USN-6521-1
ZDI-23-1593

Produtos afetados

Almalinux
Centos
Gimp
Linuxmint
Red Hat
Red Os
Rocky Linux
Ubuntu