Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Users should avoid opening untrusted PCX image files with GIMP. If GIMP is not required, consider removing the `gimp` package to eliminate this attack vector.
Fri, 27 Mar 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gnome
Gnome gimp |
|
| Vendors & Products |
Gnome
Gnome gimp |
Fri, 27 Mar 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 26 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP’s PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS). | A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS). |
| Title | Gimp: gimp: memory disclosure and denial of service via specially crafted pcx image | Gimp: gimp:memory disclosure and denial of service via specially crafted pcx image |
| Metrics |
ssvc
|
Thu, 26 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP’s PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS). | |
| Title | Gimp: gimp: memory disclosure and denial of service via specially crafted pcx image | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-193 | |
| CPEs | cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-03-26T12:58:48.737Z
Reserved: 2026-03-26T11:33:19.455Z
Link: CVE-2026-4887
Updated: 2026-03-26T12:58:42.644Z
Status : Awaiting Analysis
Published: 2026-03-26T13:16:30.780
Modified: 2026-03-26T15:13:15.790
Link: CVE-2026-4887
OpenCVE Enrichment
Updated: 2026-03-27T09:28:41Z