peter bassill · operator
$ cve CVE-2012-3236 JSON

CVE-2012-3236 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 10.7% (pctl 96)

Patch early

A public exploit exists.

Description

fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS10.75% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-476
On CISA KEVno
Public exploityes
Published2012-07-12
Last modified2026-06-16

Affected (1)

VendorProduct
gimpgimp

Public exploits

SourceTitleDate
exploit-dbGIMP 2.8.0 - '.FIT' File Format Denial of Service2012-06-30

References

→ the Explorer  ·  watch your stack  ·  NVD