Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 8 and 9: Critical RCE Vulnerabilities in GIMP Discovered 2023-0346

mageia
Calendar Grey December 15, 2023
Dist Mageia Esm H88
GIMP has issued a significant upgrade that tackles buffer overflow security issues for Mageia versions 8 and 9. Discover more details!
GIMP has been updated to version 2.10.36 to fix several security issues

Summary

GIMP has been updated to version 2.10.36 to fix several security issues. CVE-2023-44441: GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability CVE-2023-44442: GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability CVE-2023-44443: GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability CVE-2023-44444: GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability

References

- https://bugs.mageia.org/show_bug.cgi?id=32548

- https://www.openwall.com/lists/oss-security/2023/11/20/3

- https://www.cve.org/CVERecord?id=CVE-2023-44441

- https://www.cve.org/CVERecord?id=CVE-2023-44442

- https://www.cve.org/CVERecord?id=CVE-2023-44443

- https://www.cve.org/CVERecord?id=CVE-2023-44444

Resolution

SRPMS

- 9/core/gimp-2.10.36-1.mga9

- 8/core/gimp-2.10.36-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 15 Dec 2023
URL: https://advisories.mageia.org/MGASA-2023-0346.html
Type: security
CVE: CVE-2023-44441, CVE-2023-44442, CVE-2023-44443, CVE-2023-44444

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here