GIMP: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201209-23 / gimp |
| Release Date |
September 28, 2012 |
| Latest Revision |
September 28, 2012: 1 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| media-gfx/gimp |
<
2.6.12-r2 |
>=
2.6.12-r2 |
All supported architectures
|
Related bugreports:
#293127, #350915, #372975, #379289, #418425, #432582
Synopsis
Multiple vulnerabilities have been found in GIMP, the worst of
which allow execution of arbitrary code or Denial of Service.
2.
Impact Information
Background
GIMP is the GNU Image Manipulation Program.
Description
Multiple vulnerabilities have been discovered in GIMP. Please review the
CVE identifiers referenced below for details.
Impact
A remote attacker could possibly execute arbitrary code with the
privileges of the process or cause a Denial of Service condition.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All GIMP users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-gfx/gimp-2.6.12-r2"
|
4.
References
|