Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-10666 http://linux.oracle.com/errata/ELSA-2024-10666.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: gimp-2.8.22-1.0.1.el7.x86_64.rpm gimp-devel-2.8.22-1.0.1.el7.i686.rpm gimp-devel-2.8.22-1.0.1.el7.x86_64.rpm gimp-devel-tools-2.8.22-1.0.1.el7.x86_64.rpm gimp-libs-2.8.22-1.0.1.el7.i686.rpm gimp-libs-2.8.22-1.0.1.el7.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//gimp-2.8.22-1.0.1.el7.src.rpm Related CVEs: CVE-2023-44442 CVE-2023-44444 Description of changes: [2:2.8.22-1.0.1] - Fix CVE-2023-44442 [Orabug: 37344570] - Fix CVE-2023-44444 _______________________________________________ El-errata mailing list
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for gimp ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3106-1 Rating: moderate References: #1201192 Cross-References: CVE-2022-32990 CVSS scores: CVE-2022-32990 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2022-32990 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Linux Enterprise Workstation Extension 15-SP4 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gimp fixes the following issues: - CVE-2022-32990: Fixed an unhandled exception which may lead to denial of service (bsc#1201192). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-3106=1 - SUSE Linux Enterprise Workstation Extension 15-SP4: zypper in -t patch SUSE-SLE-Product-WE-15-SP4-2022-3106=1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4: zypper in -t patchSUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2022-3106=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): gimp-2.10.30-150400.3.6.2 gimp-debuginfo-2.10.30-150400.3.6.2 gimp-debugsource-2.10.30-150400.3.6.2 gimp-devel-2.10.30-150400.3.6.2 gimp-devel-debuginfo-2.10.30-150400.3.6.2 gimp-plugin-aa-2.10.30-150400.3.6.2 gimp-plugin-aa-debuginfo-2.10.30-150400.3.6.2 libgimp-2_0-0-2.10.30-150400.3.6.2 libgimp-2_0-0-debuginfo-2.10.30-150400.3.6.2 libgimpui-2_0-0-2.10.30-150400.3.6.2 libgimpui-2_0-0-debuginfo-2.10.30-150400.3.6.2 - openSUSE Leap 15.4 (x86_64): libgimp-2_0-0-32bit-2.10.30-150400.3.6.2 libgimp-2_0-0-32bit-debuginfo-2.10.30-150400.3.6.2 libgimpui-2_0-0-32bit-2.10.30-150400.3.6.2 libgimpui-2_0-0-32bit-debuginfo-2.10.30-150400.3.6.2 - openSUSE Leap 15.4 (noarch): gimp-lang-2.10.30-150400.3.6.2 - SUSE Linux Enterprise Workstation Extension 15-SP4 (x86_64): gimp-2.10.30-150400.3.6.2 gimp-debuginfo-2.10.30-150400.3.6.2 gimp-debugsource-2.10.30-150400.3.6.2 gimp-devel-2.10.30-150400.3.6.2 gimp-devel-debuginfo-2.10.30-150400.3.6.2 libgimp-2_0-0-2.10.30-150400.3.6.2 libgimp-2_0-0-debuginfo-2.10.30-150400.3.6.2 libgimpui-2_0-0-2.10.30-150400.3.6.2 libgimpui-2_0-0-debuginfo-2.10.30-150400.3.6.2 - SUSE Linux Enterprise Workstation Extension 15-SP4 (noarch): gimp-lang-2.10.30-150400.3.6.2 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (aarch64 ppc64le s390x): gimp-debuginfo-2.10.30-150400.3.6.2 gimp-debugsource-2.10.30-150400.3.6.2 libgimp-2_0-0-2.10.30-150400.3.6.2 libgimp-2_0-0-debuginfo-2.10.30-150400.3.6.2 libgimpui-2_0-0-2.10.30-150400.3.6.2 libgimpui-2_0-0-debuginfo-2.10.30-150400.3.6.2 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (aarch64): gimp-2.10.30-150400.3.6.2 gimp-devel-2.10.30-150400.3.6.2 gimp-devel-debuginfo-2.10.30-150400.3.6.2 gimp-plugin-aa-2.10.30-150400.3.6.2 gimp-plugin-aa-debuginfo-2.10.30-150400.3.6.2 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (noarch): gimp-lang-2.10.30-150400.3.6.2 References: https://www.suse.com/security/cve/CVE-2022-32990.html https://bugzilla.suse.com/1201192 . SUSE has issued a security update for gimp addressing a denial of service vulnerability rated with moderate severity. It is recommended to apply this patch to improve system security.. SUSE gimp patch, denial service issue, SUSE security update. . LinuxSecurity.com Team
Moderate: gimp security update. Date: Mon, 9 Dec 2013 16:00:40 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: gimp on SL5.x, SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Moderate: gimp security update Advisory ID: SLSA-2013:1778-1 Issue Date: 2013-12-03 CVE Numbers: CVE-2012-5576 CVE-2013-1913 CVE-2013-1978 -- A stack-based buffer overflow flaw, a heap-based buffer overflow, and an integer overflow flaw were found in the way GIMP loaded certain X Window System (XWD) image dump files. A remote attacker could provide a specially crafted XWD image file that, when processed, would cause the XWD plug-in to crash or, potentially, execute arbitrary code with the privileges of the user running the GIMP. (CVE-2012-5576, CVE-2013-1913, CVE-2013-1978) The GIMP must be restarted for the update to take effect. -- SL5 x86_64 gimp-2.2.13-3.el5_10.x86_64.rpm gimp-debuginfo-2.2.13-3.el5_10.i386.rpm gimp-debuginfo-2.2.13-3.el5_10.x86_64.rpm gimp-libs-2.2.13-3.el5_10.i386.rpm gimp-libs-2.2.13-3.el5_10.x86_64.rpm gimp-devel-2.2.13-3.el5_10.i386.rpm gimp-devel-2.2.13-3.el5_10.x86_64.rpm i386 gimp-2.2.13-3.el5_10.i386.rpm gimp-debuginfo-2.2.13-3.el5_10.i386.rpm gimp-libs-2.2.13-3.el5_10.i386.rpm gimp-devel-2.2.13-3.el5_10.i386.rpm SL6 x86_64 gimp-2.6.9-6.el6_5.x86_64.rpm gimp-debuginfo-2.6.9-6.el6_5.x86_64.rpm gimp-help-browser-2.6.9-6.el6_5.x86_64.rpm gimp-libs-2.6.9-6.el6_5.x86_64.rpm gimp-debuginfo-2.6.9-6.el6_5.i686.rpm gimp-devel-2.6.9-6.el6_5.i686.rpm gimp-devel-2.6.9-6.el6_5.x86_64.rpm gimp-devel-tools-2.6.9-6.el6_5.x86_64.rpm gimp-libs-2.6.9-6.el6_5.i686.rpm i386 gimp-2.6.9-6.el6_5.i686.rpm gimp-debuginfo-2.6.9-6.el6_5.i686.rpm gimp-help-browser-2.6.9-6.el6_5.i686.rpm gimp-libs-2.6.9-6.el6_5.i686.rpm gimp-devel-2.6.9-6.el6_5.i686.rpm gimp-devel-tools-2.6.9-6.el6_5.i686.rpm - Scientific Linux Development Team . GIMP security patch resolves several severe vulnerabilities posing remote codeexecution threats in Scientific Linux SL5.x and SL6.x.. GIMP Update, Scientific Linux, Buffer Overflow, Remote Code Execution, Security Advisory. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.