6.6 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): HIGH
Gimp: gimp integer overflow
A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP "Despeckle" plug-in. The issue occurs due to unchecked multiplication of image dimensions, such as width, height, and bytes-per-pixel (img_bpp), which can result in allocating insufficient memory and subsequently performing out-of-bounds writes. This issue could lead to heap corruption, a potential denial of service (DoS), or arbitrary code execution in certain scenarios.
References
Affected products
- <3.0.4
Matching in nixpkgs
pkgs.zigimports
Automatically remove unused imports and globals from Zig files
pkgs.gimpPlugins.bimp
Batch Image Manipulation Plugin for GIMP
pkgs.gimpPlugins.gimp
GNU Image Manipulation Program
pkgs.gimpPlugins.gmic
GIMP plugin for the G'MIC image processing framework
pkgs.gimp-with-plugins
GNU Image Manipulation Program
pkgs.gimp2Plugins.bimp
Batch Image Manipulation Plugin for GIMP
pkgs.gimp2Plugins.gimp
GNU Image Manipulation Program
pkgs.gimp2Plugins.gmic
GIMP plugin for the G'MIC image processing framework
pkgs.gimp3Plugins.gimp
GNU Image Manipulation Program
pkgs.gimp3Plugins.gmic
GIMP plugin for the G'MIC image processing framework
pkgs.gimp2-with-plugins
GNU Image Manipulation Program
pkgs.gimp3-with-plugins
GNU Image Manipulation Program
pkgs.gimpPlugins.fourier
GIMP plug-in to do the fourier transform
pkgs.gimp2Plugins.fourier
GIMP plug-in to do the fourier transform
pkgs.gimpPlugins.farbfeld
Gimp plug-in for the farbfeld image format
-
nixos-unstable 2019-08-12
- nixpkgs-unstable 2019-08-12
- nixos-unstable-small 2019-08-12
pkgs.gimp2Plugins.farbfeld
Gimp plug-in for the farbfeld image format
-
nixos-25.11 2019-08-12
- nixpkgs-25.11-darwin 2019-08-12
pkgs.gimpPlugins.lightning
None
pkgs.gimpPlugins.lqrPlugin
None
pkgs.gimpPlugins.texturize
None
-
nixos-unstable 2.2+unstable=2021-12-03
- nixpkgs-unstable 2.2+unstable=2021-12-03
- nixos-unstable-small 2.2+unstable=2021-12-03
pkgs.gimp2Plugins.lightning
None
pkgs.gimp2Plugins.lqrPlugin
None
pkgs.gimp2Plugins.texturize
None
-
nixos-25.11 2.2+unstable=2021-12-03
- nixpkgs-25.11-darwin 2.2+unstable=2021-12-03
pkgs.gimp3Plugins.lightning
None
pkgs.gimpPlugins.gimplensfun
GIMP plugin to correct lens distortion using the lensfun library and database
-
nixos-unstable 2018-10-21
- nixpkgs-unstable 2018-10-21
- nixos-unstable-small 2018-10-21
pkgs.gimp2Plugins.gimplensfun
GIMP plugin to correct lens distortion using the lensfun library and database
-
nixos-25.11 2018-10-21
- nixpkgs-25.11-darwin 2018-10-21
pkgs.gimpPlugins.resynthesizer
None
pkgs.gimpPlugins.waveletSharpen
None
pkgs.gimp2Plugins.waveletSharpen
None
Package maintainers
-
@jtojnar Jan Tojnar <jtojnar@gmail.com>
-
@sikmir Nikolay Korotkiy <sikmir@disroot.org>
-
@jmbaur Jared Baur <jaredbaur@fastmail.com>