[Git][security-tracker-team/security-tracker][master] gimp fixed in sid

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sat Sep 12 15:57:59 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
33bcbd8f by Moritz Muehlenhoff at 2026-09-12T16:57:37+02:00
gimp fixed in sid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -15228,7 +15228,7 @@ CVE-2026-75807 (The SAML Single Sign On \u2013 SSO Login plugin for WordPress is
 CVE-2026-14494 (The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-82343 (A flaw was found in the file-psd plugin in GIMP. When processing a spe ...)
-	- gimp <unfixed> (bug #1146135)
+	- gimp 3.2.6-1 (bug #1146135)
 	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16587
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/6b6a3e6d8ccdf2a7d6488d0df28ec033a9801a38
@@ -15718,24 +15718,24 @@ CVE-2026-9548 (An improper neutralization of input during web page generation ('
 CVE-2026-9491 (A server-ide request forgery (SSRF) vulnerability in webhook in Synolo ...)
 	NOT-FOR-US: Synology
 CVE-2026-82330 (A flaw was found in the file-pvr plugin in GIMP. When processing a spe ...)
-	- gimp <unfixed> (bug #1146134)
+	- gimp 3.2.6-1 (bug #1146134)
 	[trixie] - gimp <not-affected> (Vulnerable code not present)
 	[bookworm] - gimp <not-affected> (Vulnerable code not present)
 	[bullseye] - gimp <not-affected> (Vulnerable code not present)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16586
-	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/ae584e9338774388db9705bd8ff5cb4bd308268a
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/ae584e9338774388db9705bd8ff5cb4bd308268a (GIMP_3_2_6)
 CVE-2026-82328 (A flaw was found in the file-ico plugin in GIMP. When processing a spe ...)
-	- gimp <unfixed> (bug #1146133)
+	- gimp 3.2.6-1 (bug #1146133)
 	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16585
-	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/f59f677d849d5a2e1e689008d675f720c72e516e
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/f59f677d849d5a2e1e689008d675f720c72e516e (GIMP_3_2_6)
 CVE-2026-82327 (A flaw was found in libsolv, a dependency-resolution library used by R ...)
 	- libsolv <unfixed> (bug #1147424)
 	[trixie] - libsolv <no-dsa> (Minor issue)
 	[bookworm] - libsolv <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2525602
 CVE-2026-82324 (A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When proce ...)
-	- gimp <unfixed> (bug #1146132; unimportant)
+	- gimp 3.2.6-1 (bug #1146132; unimportant)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16584
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/2fba61f28efaebdc170e951e499e42820fbf633a
 	NOTE: Building of optional Plug-In for Amiga IFF/ILBM not enabled.
@@ -18819,12 +18819,12 @@ CVE-2026-7487 (GitLab has remediated an issue in GitLab EE affecting all version
 CVE-2026-79940 (Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions pr ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-79902 (A flaw was found in the Seattle FilmWorks plugin in GIMP. When process ...)
-	- gimp <unfixed> (bug #1145872)
+	- gimp 3.2.6-1 (bug #1145872)
 	[trixie] - gimp <not-affected> (Vulnerable code not present)
 	[bookworm] - gimp <not-affected> (Vulnerable code not present)
 	[bullseye] - gimp <not-affected> (Vulnerable code not present)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16582
-	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/fa9503bcc41e41ac0a5ae162a97486c79a7790ce
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/fa9503bcc41e41ac0a5ae162a97486c79a7790ce (GIMP_3_2_6)
 CVE-2026-78237 (Insufficient input validation in ABR allows a low-privileged user to i ...)
 	NOT-FOR-US: ABR
 CVE-2026-78236 (An insecure PIN derivation mechanism in ABR allows a low-privileged us ...)
@@ -19208,10 +19208,10 @@ CVE-2026-80138 (ClipBucket V5's web installer fails to properly validate or esca
 CVE-2026-80104 (DB-GPT builds the destination path for an uploaded skill from the mult ...)
 	NOT-FOR-US: DB-GPT
 CVE-2026-80101 (A flaw was found in the file-xwd plugin in GIMP. When processing a spe ...)
-	- gimp <unfixed> (bug #1145871)
+	- gimp 3.2.6-1 (bug #1145871)
 	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16583
-	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/e78fe7ae2a8d3341f6e862c0426265791d5975e6
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/e78fe7ae2a8d3341f6e862c0426265791d5975e6 (GIMP_3_2_6)
 CVE-2026-79912 (A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. ...)
 	NOT-FOR-US: TOTOLINK
 CVE-2026-79911 (A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7 ...)
@@ -22018,15 +22018,15 @@ CVE-2026-8173 (The web GUI of affected Murrelektronik Xelity switches logs MAC a
 CVE-2026-78541 (A stored OS command injection vulnerability exists in the parent-contr ...)
 	NOT-FOR-US: TPLink
 CVE-2026-78475 (A flaw was found in the file-pix (ESM) plugin in GIMP. When processing ...)
-	- gimp <unfixed> (bug #1145874)
+	- gimp 3.2.6-1 (bug #1145874)
 	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16580
-	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/27d83534e637cf160f913ac6d6388d5a5555e9d8
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/27d83534e637cf160f913ac6d6388d5a5555e9d8 (GIMP_3_2_6)
 CVE-2026-78465 (A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit buil ...)
-	- gimp <unfixed> (bug #1145875)
+	- gimp 3.2.6-1 (bug #1145875)
 	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16578
-	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/56e580c43a2de9c0005f57018013998999535e4d
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/56e580c43a2de9c0005f57018013998999535e4d (GIMP_3_2_6)
 CVE-2026-78417 (Insufficient verification of data authenticity in the IronVNC client i ...)
 	NOT-FOR-US: Devolutions
 CVE-2026-78416 (Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 bef ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/33bcbd8f0d4c9552d3a412f386aa38ca3b1837b0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/33bcbd8f0d4c9552d3a412f386aa38ca3b1837b0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/6a4f80f1/attachment.htm>


More information about the debian-security-tracker-commits mailing list