CNNVD-202512-4045 Information

CNNVD ID

CNNVD-202512-4045

CVE-2025-14423

  • CNNVD Published: 2025-12-23

Description (Chinese)

GIMP是GIMP团队的一款开源的位图图像编辑器。 GIMP存在安全漏洞,该漏洞源于解析LBM文件时,在复制到栈缓冲区前缺乏对用户提供数据长度的适当验证,可能导致栈缓冲区溢出和远程代码执行。

Description (English)

GIMP is an open-source bitmap image editor for the GIMP team. There is a security loophole in the GIMP, which stems from the lack of proper validation of the data length provided by users before copying the LBM file before copying it to the silo buffer zone, which could lead to spills and remote code implementation.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

GIMP

Published

2025-12-23

Last Modified

2026-02-24

References

https://gitlab.gnome.org/GNOME/gimp/-/commit/481cdbbb97746be1145ec3a633c567a68633c521 https://www.zerodayinitiative.com/advisories/ZDI-25-1137/

Share on: