CVE-2012-3481: Gimp

Medium severity, CVSS 6.8. EPSS: 5.1% chance of exploitation in the next 30 days.

Integer overflow in the ReadImage function in plug-ins/common/file-gif-load.c in the GIF image format plug-in in GIMP 2.8.x and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted height and len properties in a GIF image file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

Affected products

  • Gimp Gimp: up to and including 2.8.0

Published 2012-08-25. Last modified 2026-06-16.