Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-2949

24
FAUCET Score

CVE-2007-2949 describes an integer overflow vulnerability in the Gimp 2.2.15 psd.c plugin, allowing remote attackers to execute arbitrary code. This flaw is triggered by specially crafted PSD files containing large width or height values and affects Gimp and Ubuntu Linux distributions. With a CVSS score of 6.8, this vulnerability is moderately severe, requiring user interaction (opening a malicious file) but potentially leading to full compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting it is not widely targeted.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.2.15CPE matchmatch criteria
cpe:2.3:a:gimp:gimp:*:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
6.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*
7.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
7.17%
Probability of exploitation in next 30 days
EPSS Percentile
93.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0717 is in the 93rd percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: gimp-1:1.2.1-7.8.el2_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: gimp-1:1.2.3-20.9.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: gimp-1:2.0.5-7.0.7.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: gimp-2:2.2.13-2.0.7.el5
View patch

Vendor Advisories (1)

redhatCVE-2007-2949Moderate

Gimp PSD integer overflow

Jun 27, 2007

References

issues.foresightlinux.org / browse/FL-457
Broken Link
osvdb.org / 37804
Broken Link
secunia.com / advisories/25677
Broken LinkPatch
secunia.com / advisories/25949
Broken Link
secunia.com / advisories/26044
Broken Link
secunia.com / advisories/26132
Broken Link
secunia.com / advisories/26215
Broken Link
secunia.com / advisories/26384
Broken Link
secunia.com / advisories/26575
Broken Link
secunia.com / advisories/26939
Broken Link
secunia.com / advisories/28114
Broken Link
secunia.com / secunia_research/2007-63/advisory
Broken LinkPatchVendor Advisory
security.gentoo.org / glsa/glsa-200707-09.xml
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/35246
Third Party AdvisoryVDB Entry
issues.rpath.com / browse/RPL-1487
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11276
Tool Signature
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5772
Tool Signature
sunsolve.sun.com / search/document.do
Broken Link
sunsolve.sun.com / search/document.do
Broken Link
svn.gnome.org / viewcvs/gimp
Vendor Advisory
debian.org / security/2007/dsa-1335
Third Party Advisory
kb.cert.org / vuls/id/399896
Third Party AdvisoryUS Government Resource
mandriva.com / security/advisories
Broken Link
novell.com / linux/security/advisories/2007_15_sr.html
Broken Link
redhat.com / support/errata/RHSA-2007-0513.html
Broken Link
securityfocus.com / bid/24745
Broken LinkThird Party AdvisoryVDB Entry
slackware.org / security/viewer.php
Third Party Advisory
ubuntu.com / usn/usn-480-1
Third Party Advisory
vupen.com / english/advisories/2007/2421
Broken Link
vupen.com / english/advisories/2007/4241
Broken Link