Out-Of-Bounds Write Vulnerability in GIMP
CVE-2025-2761
What is CVE-2025-2761?
This vulnerability in GIMP involves an out-of-bounds write caused by improper validation of user-supplied data during the parsing of FLI files. Attackers can exploit this issue to execute arbitrary code on affected systems. To trigger the vulnerability, users must either visit a specially crafted website or open a malicious FLI file, placing them at risk if precautions are not taken.
Affected Version(s)
GIMP 2.10.38
News Articles
GIMP Image Editor Vulnerability Allows Remote Attackers to Execute Arbitrary Code
The flaw resides in the way GIMP parses X Window Dump (XWD) files—a format used for storing screenshots from X11 environments.
GIMP Image Editor Vulnerability Let Remote Attackers Arbitrary Code
Two critical security vulnerabilities discovered in the popular GIMP image editing software have been disclosed, allowing remote attackers.
References
CVSS V3.1
CVSS V3.0
Timeline
- đź“°
First article discovered by CybersecurityNews
Vulnerability published
Vulnerability Reserved
