CVE-2025-5473
massInteger Overflow Leading to RCE in GIMP ICO File Parsing
CVE-2025-5473 is an integer overflow (CWE-190) in the way GIMP parses ICO (icon) files, caused by insufficient validation of user-supplied data before writing to memory. It is triggered when a user opens a malicious ICO file or visits a malicious page that leads GIMP to process a crafted file, so user interaction is required. Successful exploitation allows a remote attacker to execute arbitrary code in the context of the current GIMP process, generally with the privileges of the logged-in user. Anyone running an affected GIMP installation that opens untrusted image files is at risk; the source data does not specify exact affected version ranges. Exploitation has not been confirmed in the wild and no public proof-of-concept is known, but EPSS assigns a 23.5% probability of exploitation within 30 days (98th percentile), and the issue was reported through the Zero Day Initiative (ZDI-CAN-26752).
What to do: Upgrade GIMP to the latest vendor release containing the ICO parser fix as soon as it is published, and check GIMP's official release notes or the ZDI advisory for the specific fixed version. Until systems are patched, do not open ICO files or untrusted images from email, downloads, or web sources with GIMP. Given the elevated EPSS score, monitor CISA KEV and vendor advisories for confirmation of active exploitation.
| GIMP (GNU Image Manipulation Program) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICO files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26752.
- Vendors
- gimp
- Products
- gimp
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.