Vulnerability record · CVE-2023-44443 · published 3 May 2024
CVE-2023-44443: GIMP PSP file parsing integer overflow enables remote code execution
Gimp · Gimp
GIMP fails to properly validate user-supplied data while parsing PSP files, causing an integer overflow before a memory write. A crafted PSP file can therefore corrupt memory and lead to code execution in the context of the GIMP process. Because GIMP is widely used on endpoints and PSP is a supported import format, the flaw matters to anyone who opens untrusted image files.
Description
GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSP files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-22096.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with a high CVSS score and near-top EPSS probability, tempered only by the required user interaction and the absence of KEV listing or known in-the-wild exploitation.
What it is
GIMP fails to properly validate user-supplied data while parsing PSP files, causing an integer overflow before a memory write. A crafted PSP file can therefore corrupt memory and lead to code execution in the context of the GIMP process. Because GIMP is widely used on endpoints and PSP is a supported import format, the flaw matters to anyone who opens untrusted image files.
Impact
An attacker who gets a victim to open a malicious PSP file can execute arbitrary code with the privileges of the GIMP process, giving full control of confidentiality, integrity and availability for that user session.
Attack surface
Reached locally by opening a crafted PSP file or visiting a malicious page that triggers the file load; the CVSS vector shows AV:L with UI:R and PR:N, so no authentication is needed but user interaction is required.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is documented in the record, but EPSS is very high at 0.936 (99.8th percentile), indicating strong predicted exploitation activity.
What to do
- Upgrade GIMP to the fixed release referenced in the vendor release notes (2.10.36 or later) and verify the installed version on all endpoints.
- Block or restrict opening of untrusted PSP files, especially from email attachments, downloads and web content.
- Configure mail and web gateways to strip or quarantine PSP attachments and block PSP downloads from untrusted sites.
- Run GIMP with least privilege and consider sandboxing or application isolation so code execution stays contained.
- Educate users not to open image files from unknown senders or untrusted sites.
Detection
- Monitor for GIMP processes spawning child processes such as cmd.exe, powershell.exe or /bin/sh, which is abnormal for image editing.
- Alert on GIMP crashes or memory corruption events tied to PSP file opens, using endpoint crash telemetry.
- Hunt for PSP files written to user download or temp directories followed by GIMP execution in the same session.
- Review file-creation and process-creation logs for GIMP writing executables or scripts outside its normal install and cache paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.gimp.org/news/2023/11/07/gimp-2-10-36-released/ | Release Notes |
| https://www.zerodayinitiative.com/advisories/ZDI-23-1593/ | Third Party Advisory |
| https://www.gimp.org/news/2023/11/07/gimp-2-10-36-released/ | Release Notes |
| https://www.zerodayinitiative.com/advisories/ZDI-23-1593/ | Third Party Advisory |
Track CVE-2023-44443 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-44443), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.