A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.
{
"binaries": [
{
"binary_version": "3.2.2-1ubuntu0.26.04.1",
"binary_name": "gimp"
},
{
"binary_version": "3.2.2-1ubuntu0.26.04.1",
"binary_name": "gimp-data"
},
{
"binary_version": "3.2.2-1ubuntu0.26.04.1",
"binary_name": "gir1.2-gimp-3.0"
},
{
"binary_version": "3.2.2-1ubuntu0.26.04.1",
"binary_name": "libgimp-3.0-0"
},
{
"binary_version": "3.2.2-1ubuntu0.26.04.1",
"binary_name": "libgimp-3.0-bin"
}
]
}