[Git][security-tracker-team/security-tracker][master] Add new batch of gimp issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 21 08:24:05 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
17cae1d2 by Salvatore Bonaccorso at 2026-08-21T09:07:14+02:00
Add new batch of gimp issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -499,21 +499,38 @@ CVE-2026-18917 (A flaw was found in libvirt. An unprivileged local user could ex
CVE-2026-18482 (Neo.mjs contains a command injection vulnerability within the FileSyst ...)
TODO: check
CVE-2026-18309 (GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerab ...)
- TODO: check
+ - gimp <unfixed>
+ NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-462/
+ NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/c760c8309d18bdf5259f1e04ced0779462c7c636
CVE-2026-18308 (GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
- TODO: check
+ - gimp <unfixed>
+ NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-461/
+ NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/d84f8e58f56681a0b4c66129c568cb796725ab9d
CVE-2026-18307 (GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution ...)
- TODO: check
+ - gimp <unfixed>
+ NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-460/
+ NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/bace3e7fd54104fe6b70c1703e9b982a4770811d
CVE-2026-18306 (GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
- TODO: check
+ - gimp <unfixed>
+ NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-459/
+ NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/76531da9732f38566e5fd8f8f80c837158511ae5
CVE-2026-18305 (GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
- TODO: check
+ - gimp <unfixed>
+ NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-458/
+ NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/0a45a2b51b877829ef523131b50c0eb2a933b8a1
CVE-2026-18304 (GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
+ - gimp <unfixed>
+ NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-457/
+ NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/ad32d22c347674fa1bb5b60935c376b673d946e7
TODO: check
CVE-2026-18303 (GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Executio ...)
- TODO: check
+ - gimp <unfixed>
+ NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-456/
+ NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/5633b362026c6e5b2beb559a10cd76fa32a47592
CVE-2026-18302 (GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution ...)
- TODO: check
+ - gimp <unfixed>
+ NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-455/
+ NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/77e1a11636fae53c922fe92273b8f4e33c7a9176
CVE-2026-18301 (GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
- gimp <unfixed>
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-454/
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/17cae1d21bbf20c852b6bc86e1dc412711562010
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/17cae1d21bbf20c852b6bc86e1dc412711562010
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/168622c4/attachment.htm>
More information about the debian-security-tracker-commits
mailing list