RHSA-2024:0675: Important: gimp security update
Important: gimp security update
Other sources
The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.Security Fix(es): gimp: dds buffer overflow RCE (CVE-2023-44441) gimp: PSD buffer overflow RCE (CVE-2023-44442) gimp: psp integer overflow RCE (CVE-2023-44443) gimp: psp off-by-one RCE (CVE-2023-44444) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0675?
RHSA-2024:0675 is classified as an important security update for GIMP.
How do I fix RHSA-2024:0675?
To fix RHSA-2024:0675, you should update GIMP to version 2.99.8-4.el9_3.
Which systems are affected by RHSA-2024:0675?
RHSA-2024:0675 affects Red Hat Enterprise Linux for x86_64, Power, and other architectures running the vulnerable GIMP package.
What are the impacted packages in RHSA-2024:0675?
The impacted packages in RHSA-2024:0675 include gimp, gimp-debuginfo, gimp-debugsource, gimp-devel-tools-debuginfo, and gimp-libs.
Is there a risk of exploitation with RHSA-2024:0675?
While RHSA-2024:0675 has a defined severity level, the risk of exploitation is mitigated by applying the recommended update.