[WID-SEC-2026-2539] GIMP Plugins: Mehrere Schwachstellen CVSS Base Score 7.8 (hoch) CVSS Temporal Score 7.0 (hoch) Remoteangriff nein Datum 27.07.2026 Stand 28.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Windows Produktbeschreibung Das "Gnu Image Manipulation Program" ist eine Open Source Software zum Bearbeiten von Bildern. Es ist auch Bestandteil vieler Linux Distributionen. Produkte 27.07.2026 Open Source GIMP <=3.2.4 Open Source GIMP file-sgi plugin <commit 672db3ce Open Source GIMP file-fits plugin <commit 89ae907f Open Source GIMP file-icns plugin <commit abb3129a Open Source GIMP file-icns plugin <commit 41ef3318 Angriff Angriff Ein lokaler Angreifer kann mehrere Schwachstellen in GIMP ausnutzen, um einen Denial of Service Angriff durchzufĂĽhren, beliebigen Code auszufĂĽhren oder vertrauliche Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple vulnerabilities in specific GIMP plugins (file-sgi, file-fits, and file-icns) allow a local attacker to cause a denial of service, execute arbitrary code, or disclose sensitive information. The CVSS base score is 7.8 (High). Affected are GIMP versions up to and including 3.2.4 and specific plugin commits prior to 672db3ce, 89ae907f, abb3129a, and 41ef3318; a mitigation is available.