[ubuntu/lunar-updates] gimp 2.10.34-1ubuntu0.23.04.1 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Wed Nov 29 14:58:57 UTC 2023
gimp (2.10.34-1ubuntu0.23.04.1) lunar-security; urgency=medium
* SECURITY UPDATE: DDS File Parsing Heap-based Buffer Overflow
- debian/patches/CVE-2023-44441-1.patch: verify header information in
plug-ins/file-dds/ddsread.c.
- debian/patches/CVE-2023-44441-2.patch: fix checks in
plug-ins/file-dds/ddsread.c.
- debian/patches/CVE-2023-44441-3.patch: add additional fixes in
plug-ins/file-dds/ddsread.c.
- CVE-2023-44441
* SECURITY UPDATE: PSD File Parsing Heap-based Buffer Overflow
- debian/patches/CVE-2023-44442.patch: add missing break statement in
plug-ins/file-psd/psd-util.c.
- CVE-2023-44442
* SECURITY UPDATE: PSP File Parsing Integer Overflow and Off-By-One
- debian/patches/CVE-2023-44443_44444.patch: check
color_palette_entries and fix buffer size in
plug-ins/common/file-psp.c.
- CVE-2023-44443
- CVE-2023-44444
Date: 2023-11-28 15:54:09.768896+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/gimp/2.10.34-1ubuntu0.23.04.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the lunar-changes
mailing list