CVE-2025-48796

A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file to trigger arbitrary code execution.
CVSS

No CVSS.

Configurations

No configuration.

History

30 Jul 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.3
v2 : unknown
v3 : unknown
References
  • () https://gitlab.gnome.org/GNOME/gimp/-/issues/9257 -
CWE CWE-121

27 May 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-27 14:15

Updated : 2025-07-30 15:15


NVD link : CVE-2025-48796

Mitre link : CVE-2025-48796


JSON object : View

Products Affected

No product.

CWE

No CWE.