Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| gimp | fixed | 3.2.4-1 | package |
Примечания
https://gitlab.gnome.org/GNOME/gimp/-/work_items/16230
Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/c1263f391fd685e41c09cd9b7555532c25e697c3 (GIMP_3_2_4)
Связанные уязвимости
CVSS3: 7.3
redhat
4 месяца назад
A flaw was found in GIMP's Seattle FilmWorks (SFW94A) loader. In load_image(), photo_date is allocated based on an unvalidated metadata separator offset and can become a 1-byte buffer before fread() writes the full metadata span into it. This could lead to heap memory corruption, potentially resulting in denial of service or arbitrary code execution.