← Vulnerability feed

Vulnerability record · CVE-2023-44443 · published 3 May 2024

CVE-2023-44443: GIMP PSP file parsing integer overflow enables remote code execution

Gimp · Gimp

GIMP fails to properly validate user-supplied data while parsing PSP files, causing an integer overflow before a memory write. A crafted PSP file can therefore corrupt memory and lead to code execution in the context of the GIMP process. Because GIMP is widely used on endpoints and PSP is a supported import format, the flaw matters to anyone who opens untrusted image files.

7.8 CVSS 3.0 High EPSS 94% · top 0.2% CWE-190 · Integer overflow
7.8CVSS 3.0 base score
94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSP files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-22096.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote code execution with a high CVSS score and near-top EPSS probability, tempered only by the required user interaction and the absence of KEV listing or known in-the-wild exploitation.

What it is

GIMP fails to properly validate user-supplied data while parsing PSP files, causing an integer overflow before a memory write. A crafted PSP file can therefore corrupt memory and lead to code execution in the context of the GIMP process. Because GIMP is widely used on endpoints and PSP is a supported import format, the flaw matters to anyone who opens untrusted image files.

Impact

An attacker who gets a victim to open a malicious PSP file can execute arbitrary code with the privileges of the GIMP process, giving full control of confidentiality, integrity and availability for that user session.

Attack surface

Reached locally by opening a crafted PSP file or visiting a malicious page that triggers the file load; the CVSS vector shows AV:L with UI:R and PR:N, so no authentication is needed but user interaction is required.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware use is documented in the record, but EPSS is very high at 0.936 (99.8th percentile), indicating strong predicted exploitation activity.

What to do

  • Upgrade GIMP to the fixed release referenced in the vendor release notes (2.10.36 or later) and verify the installed version on all endpoints.
  • Block or restrict opening of untrusted PSP files, especially from email attachments, downloads and web content.
  • Configure mail and web gateways to strip or quarantine PSP attachments and block PSP downloads from untrusted sites.
  • Run GIMP with least privilege and consider sandboxing or application isolation so code execution stays contained.
  • Educate users not to open image files from unknown senders or untrusted sites.

Detection

  • Monitor for GIMP processes spawning child processes such as cmd.exe, powershell.exe or /bin/sh, which is abnormal for image editing.
  • Alert on GIMP crashes or memory corruption events tied to PSP file opens, using endpoint crash telemetry.
  • Hunt for PSP files written to user download or temp directories followed by GIMP execution in the same session.
  • Review file-creation and process-creation logs for GIMP writing executables or scripts outside its normal install and cache paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-44443 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-59090Gimp vulnerabilityA flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user …EPSS 0.61%9.3CVE-2010-4541Gimp out-of-bounds write vulnerabilityStack-based buffer overflow in the loadit function in plug-ins/common/sphere-designer.c in the SPHERE DESIGNER plugin in GIMP 2.6.11 allows user-assi…EPSS 6.8%9.3CVE-2009-3909Gimp integer overflow vulnerabilityInteger overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary co…EPSS 8.7%9.3CVE-2009-1570Gimp integer overflow vulnerabilityInteger overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a…EPSS 8.0%9.3CVE-2009-0723Gimp integer overflow vulnerabilityMultiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependen…EPSS 5.0%9.3CVE-2009-0733Gimp out-of-bounds write vulnerabilityMultiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta…EPSS 5.5%9.1CVE-2018-12713Gimp vulnerabilityGIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated b…EPSS 1.9%8.8CVE-2026-2044Gimp use of uninitialized resource vulnerabilityGIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …EPSS 0.99%

Source: NIST National Vulnerability Database (record CVE-2023-44443), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.