GIMP 中的 Seattle FilmWorks 插件存在一个缺陷。在处理经过特殊构造的 SFW 图像文件时,该插件会在栈上分配一个可变长度数组(VLA),且未进行整数溢出检查,从而导致无界的栈分配。此问题会导致应用程序崩溃,进而引发服务拒绝(DoS)漏洞。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GNOME | GIMP | 3.1.4< * |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GNOME | GIMP | 3.1.4 ~ * | - |
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77658 | 7.8 HIGH | Dia: dia: stack buffer overflow in bus object via unvalidated handle count in project file |
| CVE-2026-77652 | 7.8 HIGH | Dia: dia: heap buffer overflow in wpg colormap parser via out-of-bounds palette index |
No comments yet