cbcvebase.
CVE-2025-5473
published 2025-06-06

CVE-2025-5473: GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected…

PriorityP264high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
12.51%
95.8th percentile
GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICO files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26752.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiangimp< gimp 2.10.34-1+deb12u3 (bookworm)gimp 2.10.34-1+deb12u3 (bookworm)
gimpgimp< 3.0.43.0.4
gimpgimp
gimpgimp>= 0 < 2.10.22-4+deb11u32.10.22-4+deb11u3
gimpgimp>= 0 < 2.10.34-1+deb12u32.10.34-1+deb12u3
gimpgimp>= 0 < 3.0.2-3.13.0.2-3.1
gimpgimp>= 0 < 3.0.2-3.13.0.2-3.1
gimpgimp>= 0 < 2.8.16-1ubuntu1.1+esm32.8.16-1ubuntu1.1+esm3
gimpgimp>= 0 < 2.8.22-1ubuntu0.1~esm32.8.22-1ubuntu0.1~esm3
gimpgimp>= 0 < 2.10.18-1ubuntu0.1+esm32.10.18-1ubuntu0.1+esm3
gimpgimp>= 0 < 2.10.30-1ubuntu0.1+esm32.10.30-1ubuntu0.1+esm3
gimpgimp>= 0 < 2.10.36-3ubuntu0.24.04.1+esm32.10.36-3ubuntu0.24.04.1+esm3

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger vector is a maliciously crafted ICO file opened by a GIMP user; hunt for GIMP processes loading unexpected or externally-sourced .ico files.
  • User interaction is required — phishing or drive-by delivery of a malicious ICO file is the expected initial access path; monitor for GIMP launched with ICO file arguments from browser download directories or email attachment staging paths.
  • Exploitation results in arbitrary code execution within the GIMP process context; monitor for anomalous child processes or network connections spawned by the gimp process after opening an ICO file.
  • ZDI tracking ID ZDI-CAN-26752 can be used to cross-reference any future PoC or exploit code releases associated with this vulnerability.
  • ·The NVD/ZDI advisory describes a remote attack vector, but Red Hat's analysis indicates remote exploitation is not possible in their software stack; treat attack vector as local/social-engineering (malicious file open) rather than network-reachable.
  • ·GIMP on Red Hat Enterprise Linux 6 is out of support scope — no patch will be issued for that platform; patched versions exist for Debian (bookworm: 2.10.34-1+deb12u3, bullseye: 2.10.22-4+deb11u3, trixie/forky/sid: 3.0.2-3.1) and Ubuntu (via USN-8082-1).

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.