CVE-2012-3481: Gimp
Medium severity, CVSS 6.8. EPSS: 5.1% chance of exploitation in the next 30 days.
Integer overflow in the ReadImage function in plug-ins/common/file-gif-load.c in the GIF image format plug-in in GIMP 2.8.x and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted height and len properties in a GIF image file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
Affected products
- Gimp Gimp: up to and including 2.8.0
Published 2012-08-25. Last modified 2026-06-16.