CVE Vulnerabilities

CVE-2023-44444

Off-by-one Error

Published: May 03, 2024 | Modified: Nov 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of PSP files. Crafted data in a PSP file can trigger an off-by-one error when calculating a location to write within a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-22097.

Weakness

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Affected Software

NameVendorStart VersionEnd Version
GimpGimp*2.10.36 (excluding)
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatgimp-2:2.8.22-1.el7_9.1*
Red Hat Enterprise Linux 8RedHatgimp:2.8-8090020240201075404.4ba4a31a*
Red Hat Enterprise Linux 8RedHatgimp:2.8-8100020250110133707.4c9c024f*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatgimp:2.8-8020020240215094418.c3a0935b*
Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceRedHatgimp:2.8-8020020240215094418.c3a0935b*
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsRedHatgimp:2.8-8020020240215094418.c3a0935b*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatgimp:2.8-8040020240209115058.70584597*
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRedHatgimp:2.8-8040020240209115058.70584597*
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRedHatgimp:2.8-8040020240209115058.70584597*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatgimp:2.8-8060020240201091518.6af1eaf0*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatgimp:2.8-8080020240201091217.0621e4ee*
Red Hat Enterprise Linux 9RedHatgimp-2:2.99.8-4.el9_3*
Red Hat Enterprise Linux 9RedHatgimp-2:2.99.8-4.el9_5*
Red Hat Enterprise Linux 9RedHatgimp-2:2.99.8-4.el9_6*
Red Hat Enterprise Linux 9.0 Extended Update SupportRedHatgimp-2:2.99.8-3.el9_0*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatgimp-2:2.99.8-4.el9_2*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatgimp-2:2.99.8-4.el9_4*
GimpUbuntubionic*
GimpUbuntuesm-apps/focal*
GimpUbuntuesm-apps/jammy*
GimpUbuntufocal*
GimpUbuntujammy*
GimpUbuntulunar*
GimpUbuntumantic*
GimpUbuntutrusty*
GimpUbuntuxenial*

Potential Mitigations

References