Change History (5)
comment:1 by , 9 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 9 months ago
| Priority: | normal → elevated |
|---|
While I was going through the GNOME Security wiki to make sure I have all of the details for security advisories, I found https://gitlab.gnome.org/GNOME/gimp/-/issues/13910 ...
It was fixed in this release, and is a remote code execution vulnerability. I downloaded the POC on my 12.3 system and tried it on the version of GIMP we shipped (which was 3.0.0-RC3). I get "/usr/lib/gimp/3.0/plug-ins/file-ico/file-ico: fatal error: Segmentation fault" , which means BLFS 12.3 is vulnerable to the issue. GIMP complained that it's internal state was corrupted as well
comment:4 by , 9 months ago
Confirmed that GIMP 3.0.4 fixes the issue. BLFS 12.3 users will need to update gegl and babl, will make sure that is mentioned in the advisory.

Overview of Changes from GIMP 3.0.2 to GIMP 3.0.4 =================================================
Core:
Graphical User Interface:
Tools:
Plug-ins:
PDB:
Build: