openSUSE-SU-2021:0027-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:0027-1
openSUSE-SU-2021:0027-1
Summary: Security update for gimp
Details: This update for gimp fixes the following issues: - CVE-2017-17784: Fixed an insufficient string validation for input names (bsc#1073624). - CVE-2017-17785: Fixed an heap-based buffer overflow in FLI import (bsc#1073625). - CVE-2017-17786: Fixed an out-of-bounds read in TGA (bsc#1073626). This update was imported from the SUSE:SLE-15:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/LKBDGMCM5XJOHFKTACI2CEISBTSKVLD3/, https://bugzilla.suse.com/1073624, https://bugzilla.suse.com/1073625, https://bugzilla.suse.com/1073626, https://www.suse.com/security/cve/CVE-2017-17784, https://www.suse.com/security/cve/CVE-2017-17785, https://www.suse.com/security/cve/CVE-2017-17786
Affected packages
Package
Name: gimp
Purl: pkg:rpm/opensuse/gimp&distro=openSUSE%20Leap%2015.1
Affected ranges
Type: ECOSYSTEM
Events:
