Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian 11: GIMP Critical Code Execution & DoS Risks DLA-4342-1

debian lts
Calendar Grey October 22, 2025
Dist Debian Esm H88
Serious security update for GIMP on Debian LTS addresses multiple critical vulnerabilities, enhancing user safety integration.
Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malfo...

Summary

CVE-2025-2760

GIMP XWD File Parsing Integer Overflow Remote Code Execution
Vulnerability. The specific flaw exists within the parsing of XWD
files. The issue results from the lack of proper validation of
user-supplied data, which can result in an integer overflow before
allocating a buffer. An attacker can leverage this vulnerability
to execute code in the context of the current process. Was
ZDI-CAN-25082.

CVE-2025-2761

GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution
Vulnerability. The specific flaw exists within the parsing of FLI
files. The issue results from the lack of proper validation of
user-supplied data, which can result in a write past the end of an
allocated buffer. An attacker can leverage this vulnerability to
execute code in the context of the current process. Was
ZDI-CAN-25100.

CVE-2025-5473

GIMP ICO File Parsing Integer Overflow Remote Code Execution

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: gimp
Version: 2.10.22-4+deb11u3
CVE ID: CVE-2025-2760 CVE-2025-2761 CVE-2025-5473 CVE-2025-6035
Debian Bug: 1105005 1107758 1116459

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here