← Vulnerability feed

Vulnerability record · CVE-2023-44444 · published 3 May 2024

CVE-2023-44444: GIMP PSP file parsing off-by-one leads to remote code execution

Gimp · Gimp

GIMP contains an off-by-one error (CWE-193) when parsing PSP image files, where crafted data causes an incorrect heap write location calculation. A remote attacker can exploit this to execute arbitrary code in the context of the GIMP process. The flaw is rated CVSS 3.0 7.8 (HIGH) and requires user interaction.

7.8 CVSS 3.0 High EPSS 56% · top 1.0% CWE-193 · CWE-193
7.8CVSS 3.0 base score
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSP files. Crafted data in a PSP file can trigger an off-by-one error when calculating a location to write within a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-22097.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 7.8 with high EPSS (99th percentile) and remote code execution impact, though user interaction and no KEV listing temper urgency.

What it is

GIMP contains an off-by-one error (CWE-193) when parsing PSP image files, where crafted data causes an incorrect heap write location calculation. A remote attacker can exploit this to execute arbitrary code in the context of the GIMP process. The flaw is rated CVSS 3.0 7.8 (HIGH) and requires user interaction.

Impact

An attacker who gets a crafted PSP file opened gains arbitrary code execution with the privileges of the GIMP process, potentially leading to full compromise of the user's session and data.

Attack surface

Reached locally by opening a malicious PSP file or visiting a malicious page that triggers GIMP to parse it; the CVSS vector (AV:L, PR:N, UI:R) indicates no authentication is needed but user interaction is required.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is 0.56404 (99th percentile), indicating a high predicted likelihood of exploitation activity. References are release notes and a ZDI advisory, with no public exploit tag.

What to do

  • Upgrade GIMP to version 2.10.36 or later, which the release notes indicate addresses this issue.
  • Apply vendor or distribution patches (e.g., Debian LTS advisory) where upgrading is not immediately possible.
  • Restrict opening of untrusted PSP files and block PSP attachments at email and web gateways.
  • Run GIMP with least privilege and avoid processing files from untrusted sources.
  • Consider sandboxing or isolating GIMP when handling untrusted image formats.

Detection

  • Monitor for GIMP processes spawning unexpected child processes or making unusual network connections after opening image files.
  • Hunt for crashes or abnormal terminations of GIMP when parsing PSP files, which may indicate exploitation attempts.
  • Track file creation or download of PSP files from untrusted sources and correlate with GIMP execution.
  • Review endpoint logs for heap corruption indicators or exploit-related behavior in the GIMP process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-44444 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-59090Gimp vulnerabilityA flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user …EPSS 0.61%9.3CVE-2010-4541Gimp out-of-bounds write vulnerabilityStack-based buffer overflow in the loadit function in plug-ins/common/sphere-designer.c in the SPHERE DESIGNER plugin in GIMP 2.6.11 allows user-assi…EPSS 6.8%9.3CVE-2009-3909Gimp integer overflow vulnerabilityInteger overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary co…EPSS 8.7%9.3CVE-2009-1570Gimp integer overflow vulnerabilityInteger overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a…EPSS 8.0%9.3CVE-2009-0723Gimp integer overflow vulnerabilityMultiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependen…EPSS 5.0%9.3CVE-2009-0733Gimp out-of-bounds write vulnerabilityMultiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta…EPSS 5.5%9.1CVE-2018-12713Gimp vulnerabilityGIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated b…EPSS 1.9%8.8CVE-2026-2044Gimp use of uninitialized resource vulnerabilityGIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …EPSS 0.99%

Source: NIST National Vulnerability Database (record CVE-2023-44444), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.