CVE-2026-4887
EUVD-2026-1616626.03.2026, 13:16
A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gimp | gimp | 𝑥 < 3.2.0 |
| gimp | gimp | 3.2.0:rc1 |
| gimp | gimp | 3.2.0:rc2 |
| gimp | gimp | 3.2.0:rc3 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration