Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2016-2589

Опубликовано: 09 нояб. 2016
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2016-2589: gimp security, bug fix, and enhancement update (MODERATE)

gimp [2:2.8.16-3]

  • fix multiple use-after-free bugs when parsing XCF channel and layer properties (#1348617)

[2:2.8.16-2]

  • add back obsoletes necessary for RHEL

[2:2.8.16-1]

  • version 2.8.16

[2:2.8.14-3]

  • export-dialog-destroyed-crash patch: avoid subsequent warnings

[2:2.8.14-2]

  • fix linking problem
  • use %buildroot macro consistently again

[2:2.8.14-2]

  • avoid destroying dialog and occasional crashes while exporting (#1215905)

[2:2.8.14-1.2]

[2:2.8.14-1.1]

  • Use better AppData screenshots

[2:2.8.14-1]

  • version 2.8.14

[2:2.8.10-6.2]

[2:2.8.10-6.1]

[2:2.8.10-6]

  • remove ancient obsoletes (#1002109)

[2:2.8.10-5]

  • cope with freetype >= 2.5.1 include madness

[2:2.8.10-5]

  • remove BRs contained in the minimal build environment
  • group BRs into libraries and tools
  • remove various old cruft
  • ship RPM macros for packaging plug-ins e.a. (#1063144)

[2:2.8.10-4]

  • avoid buffer overflows in file-xwd plug-in (CVE-2013-1913, CVE-2013-1978)

gimp-help [2.8.2-1]

  • version 2.8.2
  • use %global instead of %define
  • fix website and source URLs

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

gimp

2.8.16-3.el7

gimp-devel

2.8.16-3.el7

gimp-devel-tools

2.8.16-3.el7

gimp-help

2.8.2-1.el7

gimp-help-ca

2.8.2-1.el7

gimp-help-da

2.8.2-1.el7

gimp-help-de

2.8.2-1.el7

gimp-help-el

2.8.2-1.el7

gimp-help-en_GB

2.8.2-1.el7

gimp-help-es

2.8.2-1.el7

gimp-help-fr

2.8.2-1.el7

gimp-help-it

2.8.2-1.el7

gimp-help-ja

2.8.2-1.el7

gimp-help-ko

2.8.2-1.el7

gimp-help-nl

2.8.2-1.el7

gimp-help-nn

2.8.2-1.el7

gimp-help-pt_BR

2.8.2-1.el7

gimp-help-ru

2.8.2-1.el7

gimp-help-sl

2.8.2-1.el7

gimp-help-sv

2.8.2-1.el7

gimp-help-zh_CN

2.8.2-1.el7

gimp-libs

2.8.16-3.el7

Oracle Linux x86_64

gimp

2.8.16-3.el7

gimp-devel

2.8.16-3.el7

gimp-devel-tools

2.8.16-3.el7

gimp-help

2.8.2-1.el7

gimp-help-ca

2.8.2-1.el7

gimp-help-da

2.8.2-1.el7

gimp-help-de

2.8.2-1.el7

gimp-help-el

2.8.2-1.el7

gimp-help-en_GB

2.8.2-1.el7

gimp-help-es

2.8.2-1.el7

gimp-help-fr

2.8.2-1.el7

gimp-help-it

2.8.2-1.el7

gimp-help-ja

2.8.2-1.el7

gimp-help-ko

2.8.2-1.el7

gimp-help-nl

2.8.2-1.el7

gimp-help-nn

2.8.2-1.el7

gimp-help-pt_BR

2.8.2-1.el7

gimp-help-ru

2.8.2-1.el7

gimp-help-sl

2.8.2-1.el7

gimp-help-sv

2.8.2-1.el7

gimp-help-zh_CN

2.8.2-1.el7

gimp-libs

2.8.16-3.el7

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 9 лет назад

Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.

CVSS3: 2.5
redhat
около 9 лет назад

Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.

CVSS3: 7.8
nvd
около 9 лет назад

Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.

CVSS3: 7.8
debian
около 9 лет назад

Use-after-free vulnerability in the xcf_load_image function in app/xcf ...

suse-cvrf
около 9 лет назад

Security update for gimp