Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-50817

Опубликовано: 05 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-50817: gimp security update (IMPORTANT)

[2:3.0.4-4.9]

  • fix CVE-2026-42169

[2:3.0.4-4.8]

  • fix CVE-2026-66758
  • fix CVE-2026-66759

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

gimp

3.0.4-4.el9_8.9

gimp-libs

3.0.4-4.el9_8.9

Oracle Linux x86_64

gimp

3.0.4-4.el9_8.9

gimp-libs

3.0.4-4.el9_8.9

Связанные уязвимости

CVSS3: 7.3
ubuntu
7 дней назад

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening a specially crafted image file, potentially leading to code execution.

CVSS3: 7.3
redhat
7 дней назад

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening a specially crafted image file, potentially leading to code execution.

CVSS3: 7.3
nvd
7 дней назад

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening a specially crafted image file, potentially leading to code execution.

CVSS3: 7.3
debian
7 дней назад

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) ...

suse-cvrf
7 дней назад

Security update for gimp