Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-40751

Опубликовано: 16 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-40751: gimp security update (IMPORTANT)

[2:3.0.4-4.6]

  • fix CVE-2026-58384
  • Resolves: RHEL-192536

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

gimp

3.0.4-4.el9_8.7

gimp-libs

3.0.4-4.el9_8.7

Oracle Linux x86_64

gimp

3.0.4-4.el9_8.7

gimp-libs

3.0.4-4.el9_8.7

Связанные CVE

Связанные уязвимости

CVSS3: 7.3
ubuntu
25 дней назад

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
redhat
4 месяца назад

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
nvd
25 дней назад

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
debian
25 дней назад

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE ...

CVSS3: 7.3
ubuntu
25 дней назад

A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.