[Git][security-tracker-team/security-tracker][master] Add three new gimp issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Sep 14 20:44:08 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ae1269ea by Salvatore Bonaccorso at 2026-09-14T21:43:32+02:00
Add three new gimp issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -24,11 +24,20 @@ CVE-2026-90957 (Affected versions of MISP serve uploaded SVG images inline witho
CVE-2026-90955 (Affected versions of MISP\u2019s interactive CLI shell do not reliably ...)
- misp <itp> (bug #1144317)
CVE-2026-90949 (A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When proc ...)
- TODO: check
+ - gimp <unfixed>
+ NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16753
+ NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2998
+ NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/0ff8049449b00bdd906faad7fcea091de8aa00a5
CVE-2026-90948 (A flaw was found in GIMP's ICO file loader. When processing an ICO fil ...)
- TODO: check
+ - gimp <unfixed>
+ NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16742
+ NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/123d6360b8d7e2a00a9d913889ee9cdca88e2380 (master)
+ NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/07c8d365873dc748a11a2df19e7a9eeab1c10667 (gimp-3-2 branch)
CVE-2026-90947 (A flaw was found in GIMP. When processing a specially crafted lighting ...)
- TODO: check
+ - gimp <unfixed>
+ NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16682
+ NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2960
+ NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/8a680c38fe84d529255e6b2916951ae7c480ed2c (master)
CVE-2026-90946 (DeepWiki-Open through commit d92819a contains an arbitrary file read v ...)
TODO: check
CVE-2026-90945 (Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT tok ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ae1269ea8b47e118ddbc4a71f13ea280c6c1db01
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ae1269ea8b47e118ddbc4a71f13ea280c6c1db01
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/345f5ff5/attachment.htm>
More information about the debian-security-tracker-commits
mailing list