Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21171-1

Опубликовано: 29 июн. 2026
Источник: suse-cvrf

Описание

Security update for gimp

This update for gimp fixes the following issues:

Changes in gimp:

  • CVE-2026-40917: plug-ins: Clean up ICNS file loading (bsc#1262199).

Список пакетов

openSUSE Leap 16.0
gimp-3.0.8-bp160.4.1
gimp-devel-3.0.8-bp160.4.1
gimp-extension-goat-excercises-3.0.8-bp160.4.1
gimp-lang-3.0.8-bp160.4.1
gimp-plugin-aa-3.0.8-bp160.4.1
gimp-plugin-python3-3.0.8-bp160.4.1
gimp-vala-3.0.8-bp160.4.1
libgimp-3_0-0-3.0.8-bp160.4.1
libgimpui-3_0-0-3.0.8-bp160.4.1

Описание

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that process such files.


Затронутые продукты
openSUSE Leap 16.0:gimp-3.0.8-bp160.4.1
openSUSE Leap 16.0:gimp-devel-3.0.8-bp160.4.1
openSUSE Leap 16.0:gimp-extension-goat-excercises-3.0.8-bp160.4.1
openSUSE Leap 16.0:gimp-lang-3.0.8-bp160.4.1

Ссылки