CNNVD-202510-3952 Information

CNNVD ID

CNNVD-202510-3952

CVE-2025-10934

  • CNNVD Published: 2025-10-29

Description (Chinese)

GIMP是GIMP团队的一款开源的位图图像编辑器。 GIMP存在安全漏洞,该漏洞源于解析XWD文件时未正确验证用户提供数据的长度,可能导致堆缓冲区溢出和远程代码执行。

Description (English)

GIMP is an open-source bitmap image editor for the GIMP team. There is a security loophole in the GIMP, which stems from the incorrect verification of the length of data provided by users when the XWD file is deciphered, which may lead to spills over the buffer zone and remote code execution.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

GIMP

Published

2025-10-29

Last Modified

2026-02-24

References

https://www.zerodayinitiative.com/advisories/ZDI-25-978/ https://gitlab.gnome.org/GNOME/gimp/-/commit/5c3e2122d53869599d77ef0f1bdece117b24fd7c https://vigilance.fr/vulnerability/GIMP-buffer-overflow-via-XWD-load-xwd-f2-d16-b16-48614

Patch

https://www.gimp.org/

Share on: