CyberRota Analysis
AI-GeneratedA vulnerability in the file-ico plugin of GIMP allows for improper validation of the palette count parameter when processing specially crafted ICO image files, leading to heap out-of-bounds reads. This flaw can cause application crashes, resulting in denial of service and potential disclosure of sensitive information from heap memory. Users and organizations utilizing GIMP, particularly those handling untrusted image files, should prioritize addressing this issue to mitigate risks.
Original NVD Description
A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
Related CVEs
Other vulnerabilities affecting the same vendor(s)