Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| gimp | fixed | 3.2.4-1 | package | |
| gimp | not-affected | trixie | package | |
| gimp | not-affected | bookworm | package | |
| gimp | not-affected | bullseye | package |
Примечания
https://gitlab.gnome.org/GNOME/gimp/-/work_items/16212
Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/de76a6044f4b9d7cf126056dd3e408aad97d2552 (GIMP_3_2_4)
Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/6395c37425cc2bf81300ffffadc9e3e75f6c0ecd (GIMP_3_1_2)
Связанные уязвимости
CVSS3: 7.3
redhat
5 месяцев назад
A flaw was found in GIMP's Jeff's Image Format (JIF) parser. A heap-based out-of-bounds write occurs in the ReadJeffsImage() function when a crafted JIF file supplies an invalid bits-per-pixel value that causes the unpack loop to write beyond the destination buffer. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.