Описание
Security update for gimp
gimp was updated to fix one security issue.
This security issue was fixed:
- CVE-2016-4994: Use-after-free vulnerabilities in the channel and layer properties parsing process (bsc#986021).
Список пакетов
SUSE Linux Enterprise Software Development Kit 11 SP4
gimp-2.6.2-3.34.47.1
gimp-devel-2.6.2-3.34.47.1
gimp-lang-2.6.2-3.34.47.1
gimp-plugins-python-2.6.2-3.34.47.1
Ссылки
- Link for SUSE-SU-2016:1827-1
- E-Mail link for SUSE-SU-2016:1827-1
- SUSE Security Ratings
- SUSE Bug 986021
- SUSE CVE CVE-2016-4994 page
Описание
Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.
Затронутые продукты
SUSE Linux Enterprise Software Development Kit 11 SP4:gimp-2.6.2-3.34.47.1
SUSE Linux Enterprise Software Development Kit 11 SP4:gimp-devel-2.6.2-3.34.47.1
SUSE Linux Enterprise Software Development Kit 11 SP4:gimp-lang-2.6.2-3.34.47.1
SUSE Linux Enterprise Software Development Kit 11 SP4:gimp-plugins-python-2.6.2-3.34.47.1
Ссылки
- CVE-2016-4994
- SUSE Bug 986021