← Back

CVE-2026-4887

nvd nist
Published: Mar 26, 2026Modified: Jun 17, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Exploitability: 1.8 / Impact: 5.2
Source: NVD

Description

A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).

Affected (4)

Products: Gimp: Gimp
1 product
Gimp
Configuration A
4 vulnerable · 4 platform
Vulnerable SoftwareAffected Versions
Gimp
Before 3.2.0
Version 3.2.0 rc1
Version 3.2.0 rc2
Version 3.2.0 rc3
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 6.0
Redhat
Enterprise Linux
Version 7.0
Redhat
Enterprise Linux
Version 8.0
Redhat
Enterprise Linux
Version 9.0

References (14)

Timeline

No history available yet.