GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability
No sign of exploitation. No public exploitation artifact known so far.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
GIMP has a flaw when opening PSP image files that allows attackers to run malicious code on your computer. An attacker can create a specially crafted PSP file that, when opened in GIMP, executes harmful programs.
An integer overflow vulnerability exists in GIMP's PSP file parser due to insufficient validation of user-supplied data. This allows a remote attacker to craft a malicious PSP file that triggers a memory write vulnerability, enabling arbitrary code execution in the context of the GIMP process when the file is opened.