Integer Overflow or Wraparound Affecting gimp package, versions [,3.1.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.09% (27th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-GIMP-10645533
  • published7 Jul 2025
  • disclosed6 Apr 2025
  • creditMichael Randrianantenaina

Introduced: 6 Apr 2025

CVE-2025-2760  (opens in a new tab)
CWE-190  (opens in a new tab)

How to fix?

Upgrade gimp to version 3.1.2 or higher.

Overview

Affected versions of this package are vulnerable to Integer Overflow or Wraparound via the DDS import routine. An attacker can lead to an application crash or potentially remote code execution by providing the user with a malicious file that will cause an overflow before allocating a buffer.

Note: While the vulnerability has been reported for XWD files, according to this comment by the maintainer, it applies to DDS files; This is likely a discrepancy due to the incorrect file extension being used in the PoC provided during reporting.

CVSS Base Scores

version 4.0
version 3.1