Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
17cae1d2 by Salvatore Bonaccorso at 2026-08-21T09:07:14+02:00
Add new batch of gimp issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -499,21 +499,38 @@ CVE-2026-18917 (A flaw was found in libvirt. An 
unprivileged local user could ex
 CVE-2026-18482 (Neo.mjs contains a command injection vulnerability within the 
FileSyst ...)
        TODO: check
 CVE-2026-18309 (GIMP APNG File Parsing Integer Overflow Remote Code Execution 
Vulnerab ...)
-       TODO: check
+       - gimp <unfixed>
+       NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-462/
+       NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/c760c8309d18bdf5259f1e04ced0779462c7c636
 CVE-2026-18308 (GIMP TIF File Parsing Integer Overflow Remote Code Execution 
Vulnerabi ...)
-       TODO: check
+       - gimp <unfixed>
+       NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-461/
+       NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/d84f8e58f56681a0b4c66129c568cb796725ab9d
 CVE-2026-18307 (GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code 
Execution ...)
-       TODO: check
+       - gimp <unfixed>
+       NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-460/
+       NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/bace3e7fd54104fe6b70c1703e9b982a4770811d
 CVE-2026-18306 (GIMP SGI File Parsing Integer Overflow Remote Code Execution 
Vulnerabi ...)
-       TODO: check
+       - gimp <unfixed>
+       NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-459/
+       NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/76531da9732f38566e5fd8f8f80c837158511ae5
 CVE-2026-18305 (GIMP TIF File Parsing Integer Overflow Remote Code Execution 
Vulnerabi ...)
-       TODO: check
+        - gimp <unfixed>
+       NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-458/
+       NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/0a45a2b51b877829ef523131b50c0eb2a933b8a1
 CVE-2026-18304 (GIMP TIF File Parsing Integer Overflow Remote Code Execution 
Vulnerabi ...)
+       - gimp <unfixed>
+       NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-457/
+       NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/ad32d22c347674fa1bb5b60935c376b673d946e7
        TODO: check
 CVE-2026-18303 (GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code 
Executio ...)
-       TODO: check
+       - gimp <unfixed>
+       NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-456/
+       NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/5633b362026c6e5b2beb559a10cd76fa32a47592
 CVE-2026-18302 (GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code 
Execution ...)
-       TODO: check
+       - gimp <unfixed>
+       NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-455/
+       NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/77e1a11636fae53c922fe92273b8f4e33c7a9176
 CVE-2026-18301 (GIMP PSD File Parsing Integer Overflow Remote Code Execution 
Vulnerabi ...)
        - gimp <unfixed>
        NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-454/



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/17cae1d21bbf20c852b6bc86e1dc412711562010

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/17cae1d21bbf20c852b6bc86e1dc412711562010
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to