Lucene search

K
mageiaGentoo FoundationMGASA-2023-0346
HistoryDec 15, 2023 - 8:57 p.m.

Updated gimp packages fix security vulnerabilities

2023-12-1520:57:51
Gentoo Foundation
advisories.mageia.org
33
gimp
update
security vulnerabilities
version 2.10.36
cve-2023-44441
cve-2023-44442
cve-2023-44443
cve-2023-44444
unix

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.1 High

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

16.2%

GIMP has been updated to version 2.10.36 to fix several security issues. CVE-2023-44441: GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability CVE-2023-44442: GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability CVE-2023-44443: GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability CVE-2023-44444: GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability

OSVersionArchitecturePackageVersionFilename
Mageia8noarchgimp< 2.10.36-1gimp-2.10.36-1.mga8
Mageia8noarchgegl< 0.4.38-1gegl-0.4.38-1.mga8
Mageia9noarchgimp< 2.10.36-1gimp-2.10.36-1.mga9

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.1 High

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

16.2%