CVE-2026-82328 - CERT CVE
ID CVE-2026-82328
Sažetak A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
Reference
CVSS
Base: 6.1
Impact: 4.2
Exploitability:1.8
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
LOW NONE HIGH
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Zadnje važnije ažuriranje 31-08-2026 - 22:15
Objavljeno 28-08-2026 - 16:18