Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| gimp | fixed | 3.2.4-1 | package | |
| gimp | not-affected | trixie | package | |
| gimp | not-affected | bookworm | package | |
| gimp | not-affected | bullseye | package |
Примечания
https://gitlab.gnome.org/GNOME/gimp/-/work_items/16231
Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/c1263f391fd685e41c09cd9b7555532c25e697c3 (GIMP_3_2_4)
Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/494f3a1452b6b4c4d61e9d3483b528c98821fb93 (GIMP_3_1_4)
Связанные уязвимости
CVSS3: 7.3
redhat
5 месяцев назад
A flaw was found in GIMP's Seattle FilmWorks (SFW94A) loader. A stack-based out-of-bounds write occurs in load_image() because a stack buffer sized as file_size - 0xE0 is later indexed using bounds based on file_size. This can corrupt stack memory and potentially lead to denial of service or arbitrary code execution.