Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
38493f79 by Salvatore Bonaccorso at 2025-11-02T08:53:20+01:00
Track fixed version for CVE-2025-10934/gimp
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1074,7 +1074,7 @@ CVE-2025-11201 (MLflow Tracking Server Model Creation
Directory Traversal Remote
CVE-2025-11200 (MLflow Weak Password Requirements Authentication Bypass
Vulnerability. ...)
NOT-FOR-US: mlflow
CVE-2025-10934 (GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code
Execution ...)
- - gimp <unfixed> (bug #1119661)
+ - gimp 3.0.4-6.2 (bug #1119661)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-978/
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/issues/14814
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/5c3e2122d53869599d77ef0f1bdece117b24fd7c
(GIMP_3_0_6)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/38493f7984fb454314236a6a369a43678c8d9aa9
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/38493f7984fb454314236a6a369a43678c8d9aa9
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits