CNNVD-202510-3953 Information
Oct 29, 2025
cve
CNNVD ID
CNNVD-202510-3953
Related CVE
- CNNVD Published: 2025-10-29
Description (Chinese)
GIMP是GIMP团队的一款开源的位图图像编辑器。 GIMP存在安全漏洞,该漏洞源于解析DCM文件时未正确验证用户提供数据的长度,可能导致堆缓冲区溢出和远程代码执行。
Description (English)
GIMP is an open-source bitmap image editor for the GIMP team. There is a security loophole in the GIMP, which stems from the incorrect verification of the length of data provided by users when deconstructing DCM files, which could lead to spills over the buffer zone and remote code implementation.
Hazard Level
Medium
Vulnerability Type
其他
Affected Vendor
GIMP
Published
2025-10-29
Last Modified
2026-02-24
References
https://gitlab.gnome.org/GNOME/gimp/-/commit/3d909166463731e94dfe62042d76225ecfc4c1e4 https://www.zerodayinitiative.com/advisories/ZDI-25-911/ https://vigilance.fr/vulnerability/GIMP-buffer-overflow-via-DCM-File-48310