GIMP is prone to a heap-based buffer-overflow vulnerability because it fails to properly bounds check user-supplied input.
Successfully exploiting this issue may allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
GIMP 2.8.22 is vulnerable; other versions may also be affected.
Information
Exploit
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
References: