Описание
Security update for gimp
This update for gimp fixes the following issues:
Changes in gimp:
- CVE-2026-40917: plug-ins: Clean up ICNS file loading (bsc#1262199).
Список пакетов
openSUSE Leap 16.0
gimp-3.0.8-bp160.4.1
gimp-devel-3.0.8-bp160.4.1
gimp-extension-goat-excercises-3.0.8-bp160.4.1
gimp-lang-3.0.8-bp160.4.1
gimp-plugin-aa-3.0.8-bp160.4.1
gimp-plugin-python3-3.0.8-bp160.4.1
gimp-vala-3.0.8-bp160.4.1
libgimp-3_0-0-3.0.8-bp160.4.1
libgimpui-3_0-0-3.0.8-bp160.4.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1262199
- SUSE CVE CVE-2026-40917 page
Описание
A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that process such files.
Затронутые продукты
openSUSE Leap 16.0:gimp-3.0.8-bp160.4.1
openSUSE Leap 16.0:gimp-devel-3.0.8-bp160.4.1
openSUSE Leap 16.0:gimp-extension-goat-excercises-3.0.8-bp160.4.1
openSUSE Leap 16.0:gimp-lang-3.0.8-bp160.4.1
Ссылки
- CVE-2026-40917
- SUSE Bug 1262199