TL;DR

A critical vulnerability in GIMP's ICNS file parser allows for remote code execution, requiring user interaction to exploit.

What happened

["Heap-based buffer overflow in GIMP's ICNS file parser"]

Why it matters for ops

['Allows remote attackers to execute arbitrary code', 'Requires user interaction (visiting a malicious page or opening a file)']

Mitigation

  • Update to the latest version of GIMP
  • Avoid visiting untrusted websites and downloading unknown files

Action items

  • Upgrade or patch immediately
  • Monitor network traffic for suspicious ICNS file transfers

Detection IOCs

  • Heap-based buffer overflow in GIMP versions prior to the fix release

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-120/