PT-2025-23000 · Gimp+9 · Gimp+9

Published

2025-01-01

·

Updated

2026-03-04

·

CVE-2025-48797

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GIMP (affected versions not specified)
Description A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2025:9162
ALSA-2025:9165
BDU:2025-09831
CESA-2025_9165
CVE-2025-48797
DLA-4342-1
DSA-5939-1
INFSA-2025_9162
INFSA-2025_9165
MGASA-2026-0012
OESA-2025-1620
RHSA-2025:9162
RHSA-2025:9165
RHSA-2025:9308
RHSA-2025:9309
RHSA-2025:9310
RHSA-2025:9314
RHSA-2025:9315
RHSA-2025:9316
RHSA-2025:9501
RHSA-2025:9569
RHSA-2025_9162
RHSA-2025_9165
SUSE-SU-2025:02164-1
USN-8075-1

Affected Products

Almalinux
Astra Linux
Centos
Debian
Gimp
Linuxmint
Red Hat
Red Os
Rocky Linux
Ubuntu