Vulnerability record · CVE-2023-44444 · published 3 May 2024
CVE-2023-44444: GIMP PSP file parsing off-by-one leads to remote code execution
Gimp · Gimp
GIMP contains an off-by-one error (CWE-193) when parsing PSP image files, where crafted data causes an incorrect heap write location calculation. A remote attacker can exploit this to execute arbitrary code in the context of the GIMP process. The flaw is rated CVSS 3.0 7.8 (HIGH) and requires user interaction.
Description
GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSP files. Crafted data in a PSP file can trigger an off-by-one error when calculating a location to write within a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-22097.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with high EPSS (99th percentile) and remote code execution impact, though user interaction and no KEV listing temper urgency.
What it is
GIMP contains an off-by-one error (CWE-193) when parsing PSP image files, where crafted data causes an incorrect heap write location calculation. A remote attacker can exploit this to execute arbitrary code in the context of the GIMP process. The flaw is rated CVSS 3.0 7.8 (HIGH) and requires user interaction.
Impact
An attacker who gets a crafted PSP file opened gains arbitrary code execution with the privileges of the GIMP process, potentially leading to full compromise of the user's session and data.
Attack surface
Reached locally by opening a malicious PSP file or visiting a malicious page that triggers GIMP to parse it; the CVSS vector (AV:L, PR:N, UI:R) indicates no authentication is needed but user interaction is required.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is 0.56404 (99th percentile), indicating a high predicted likelihood of exploitation activity. References are release notes and a ZDI advisory, with no public exploit tag.
What to do
- Upgrade GIMP to version 2.10.36 or later, which the release notes indicate addresses this issue.
- Apply vendor or distribution patches (e.g., Debian LTS advisory) where upgrading is not immediately possible.
- Restrict opening of untrusted PSP files and block PSP attachments at email and web gateways.
- Run GIMP with least privilege and avoid processing files from untrusted sources.
- Consider sandboxing or isolating GIMP when handling untrusted image formats.
Detection
- Monitor for GIMP processes spawning unexpected child processes or making unusual network connections after opening image files.
- Hunt for crashes or abnormal terminations of GIMP when parsing PSP files, which may indicate exploitation attempts.
- Track file creation or download of PSP files from untrusted sources and correlate with GIMP execution.
- Review endpoint logs for heap corruption indicators or exploit-related behavior in the GIMP process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.gimp.org/news/2023/11/07/gimp-2-10-36-released/ | Release Notes |
| https://www.zerodayinitiative.com/advisories/ZDI-23-1591/ | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2023/11/msg00015.html | |
| https://www.gimp.org/news/2023/11/07/gimp-2-10-36-released/ | Release Notes |
| https://www.zerodayinitiative.com/advisories/ZDI-23-1591/ | Third Party Advisory |
Track CVE-2023-44444 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-44444), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.