GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability
CVE-2023-44443

7.8HIGH

Key Information:

Vendor

Gimp

Status
Vendor
CVE Published:
3 May 2024

What is CVE-2023-44443?

A vulnerability has been identified in GIMP related to the parsing of PSP (Paint Shop Pro) files, which can lead to remote code execution. This flaw arises from inadequate validation of user-supplied data, resulting in potential integer overflow scenarios prior to writing to memory. Attackers may exploit this vulnerability by enticing users to interact with malicious content, such as opening a crafted file or visiting a compromised webpage. When successfully exploited, this can allow arbitrary code execution in the context of the affected GIMP process, posing significant risks for users who process PSP files.

Affected Version(s)

GIMP GIMP 2.10.34 (revision 2)

References

EPSS Score

67% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.