A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Name | Vendor | Start Version | End Version |
---|---|---|---|
Red Hat Enterprise Linux 7 Extended Lifecycle Support | RedHat | gimp-2:2.8.22-1.el7_9.2 | * |
Red Hat Enterprise Linux 8 | RedHat | gimp:2.8-8100020250614205641.4c9c024f | * |
Red Hat Enterprise Linux 8.2 Advanced Update Support | RedHat | gimp:2.8-8020020250618101631.c3a0935b | * |
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | gimp:2.8-8040020250618100956.70584597 | * |
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | gimp:2.8-8060020250618100419.6af1eaf0 | * |
Red Hat Enterprise Linux 8.6 Telecommunications Update Service | RedHat | gimp:2.8-8060020250618100419.6af1eaf0 | * |
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | RedHat | gimp:2.8-8060020250618100419.6af1eaf0 | * |
Red Hat Enterprise Linux 8.8 Telecommunications Update Service | RedHat | gimp:2.8-8080020250623120629.0621e4ee | * |
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | RedHat | gimp:2.8-8080020250623120629.0621e4ee | * |
Red Hat Enterprise Linux 9 | RedHat | gimp-2:2.99.8-4.el9_6.2 | * |
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | RedHat | gimp-2:2.99.8-3.el9_0.1 | * |
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | gimp-2:2.99.8-4.el9_2.1 | * |
Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | gimp-2:2.99.8-4.el9_4.1 | * |
Gimp | Ubuntu | focal | * |
Gimp | Ubuntu | oracular | * |
Gimp | Ubuntu | upstream | * |