GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability
Published May 3, 2024
7.8
HIGHCVSS 3.1
EPSS 56.40%
Description
GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of PSP files. Crafted data in a PSP file can trigger an off-by-one error when calculating a location to write within a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-22097.
Affected products
-
- Version GIMP 2.10.34 (revision 2)StatusaffectedConstraints-
- Version
-
- Version 0StatusaffectedConstraints<2.10.36
- Version
Red Hat Enterprise Linux 7 Extended Lifecycle Support
gimp-2:2.8.22-1.el7_9.1
Fixed · RHSA-2024:10666
Red Hat Enterprise Linux 8
gimp:2.8-8090020240201075404.4ba4a31a
Fixed · RHSA-2024:0861
Red Hat Enterprise Linux 8
gimp:2.8-8100020250110133707.4c9c024f
Fixed · RHSA-2025:0746
Red Hat Enterprise Linux 8.2 Advanced Update Support
gimp:2.8-8020020240215094418.c3a0935b
Fixed · RHSA-2024:1327
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
gimp:2.8-8020020240215094418.c3a0935b
Fixed · RHSA-2024:1327
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
gimp:2.8-8020020240215094418.c3a0935b
Fixed · RHSA-2024:1327
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
gimp:2.8-8040020240209115058.70584597
Fixed · RHSA-2024:1007
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
gimp:2.8-8040020240209115058.70584597
Fixed · RHSA-2024:1007
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
gimp:2.8-8040020240209115058.70584597
Fixed · RHSA-2024:1007
Red Hat Enterprise Linux 8.6 Extended Update Support
gimp:2.8-8060020240201091518.6af1eaf0
Fixed · RHSA-2024:0863
Red Hat Enterprise Linux 8.8 Extended Update Support
gimp:2.8-8080020240201091217.0621e4ee
Fixed · RHSA-2024:0862
Red Hat Enterprise Linux 9
gimp-2:2.99.8-4.el9_3
Fixed · RHSA-2024:0675
Red Hat Enterprise Linux 9
gimp-2:2.99.8-4.el9_5
Fixed · RHSA-2025:3617
Red Hat Enterprise Linux 9
gimp-2:2.99.8-4.el9_6
Fixed · RHSA-2025:7417
Red Hat Enterprise Linux 9.0 Extended Update Support
gimp-2:2.99.8-3.el9_0
Fixed · RHSA-2024:0716
Red Hat Enterprise Linux 9.2 Extended Update Support
gimp-2:2.99.8-4.el9_2
Fixed · RHSA-2024:0702
Red Hat Enterprise Linux 9.4 Extended Update Support
gimp-2:2.99.8-4.el9_4
Fixed · RHSA-2025:3629
Red Hat Enterprise Linux 6
gimp
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | gimp-2:2.8.22-1.el7_9.1 | Fixed | RHSA-2024:10666 |
| Red Hat Enterprise Linux 8 | gimp:2.8-8090020240201075404.4ba4a31a | Fixed | RHSA-2024:0861 |
| Red Hat Enterprise Linux 8 | gimp:2.8-8100020250110133707.4c9c024f | Fixed | RHSA-2025:0746 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | gimp:2.8-8020020240215094418.c3a0935b | Fixed | RHSA-2024:1327 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | gimp:2.8-8020020240215094418.c3a0935b | Fixed | RHSA-2024:1327 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | gimp:2.8-8020020240215094418.c3a0935b | Fixed | RHSA-2024:1327 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | gimp:2.8-8040020240209115058.70584597 | Fixed | RHSA-2024:1007 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | gimp:2.8-8040020240209115058.70584597 | Fixed | RHSA-2024:1007 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | gimp:2.8-8040020240209115058.70584597 | Fixed | RHSA-2024:1007 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | gimp:2.8-8060020240201091518.6af1eaf0 | Fixed | RHSA-2024:0863 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | gimp:2.8-8080020240201091217.0621e4ee | Fixed | RHSA-2024:0862 |
| Red Hat Enterprise Linux 9 | gimp-2:2.99.8-4.el9_3 | Fixed | RHSA-2024:0675 |
| Red Hat Enterprise Linux 9 | gimp-2:2.99.8-4.el9_5 | Fixed | RHSA-2025:3617 |
| Red Hat Enterprise Linux 9 | gimp-2:2.99.8-4.el9_6 | Fixed | RHSA-2025:7417 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | gimp-2:2.99.8-3.el9_0 | Fixed | RHSA-2024:0716 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | gimp-2:2.99.8-4.el9_2 | Fixed | RHSA-2024:0702 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | gimp-2:2.99.8-4.el9_4 | Fixed | RHSA-2025:3629 |
| Red Hat Enterprise Linux 6 | gimp | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (8)
- https://access.redhat.com/security/cve/CVE-2023-44444 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2249946 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-48784 Advisory
- https://lists.debian.org/debian-lts-announce/2023/11/msg00015.html
- https://nvd.nist.gov/vuln/detail/CVE-2023-44444
- https://www.cve.org/CVERecord?id=CVE-2023-44444
- https://www.gimp.org/news/2023/11/07/gimp-2-10-36-released/ vendor-advisoryRelease Notes
- https://www.zerodayinitiative.com/advisories/ZDI-23-1591/ x_research-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-44444 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2249946 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-48784 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/11/msg00015.html | ||
| https://nvd.nist.gov/vuln/detail/CVE-2023-44444 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-44444 | ||
| https://www.gimp.org/news/2023/11/07/gimp-2-10-36-released/ | vendor-advisoryRelease Notes | |
| https://www.zerodayinitiative.com/advisories/ZDI-23-1591/ | x_research-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.