[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2025-10934/gimp

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Nov 2 07:55:30 GMT 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
38493f79 by Salvatore Bonaccorso at 2025-11-02T08:53:20+01:00
Track fixed version for CVE-2025-10934/gimp

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1074,7 +1074,7 @@ CVE-2025-11201 (MLflow Tracking Server Model Creation Directory Traversal Remote
 CVE-2025-11200 (MLflow Weak Password Requirements Authentication Bypass Vulnerability. ...)
 	NOT-FOR-US: mlflow
 CVE-2025-10934 (GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution ...)
-	- gimp <unfixed> (bug #1119661)
+	- gimp 3.0.4-6.2 (bug #1119661)
 	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-978/
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/issues/14814
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/5c3e2122d53869599d77ef0f1bdece117b24fd7c (GIMP_3_0_6)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/38493f7984fb454314236a6a369a43678c8d9aa9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/38493f7984fb454314236a6a369a43678c8d9aa9
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251102/a9be828c/attachment.htm>


More information about the debian-security-tracker-commits mailing list