Source: gimp Version: 2.10.34-1 Severity: grave Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>
Hi, The following vulnerabilities were published for gimp. CVE-2023-44441[0]: | GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution | Vulnerability CVE-2023-44442[1]: | GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution | Vulnerability CVE-2023-44443[2]: | GIMP PSP File Parsing Integer Overflow Remote Code Execution | Vulnerability CVE-2023-44444[3]: | GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2023-44441 https://www.cve.org/CVERecord?id=CVE-2023-44441 [1] https://security-tracker.debian.org/tracker/CVE-2023-44442 https://www.cve.org/CVERecord?id=CVE-2023-44442 [2] https://security-tracker.debian.org/tracker/CVE-2023-44443 https://www.cve.org/CVERecord?id=CVE-2023-44443 [3] https://security-tracker.debian.org/tracker/CVE-2023-44444 https://www.cve.org/CVERecord?id=CVE-2023-44444 Please adjust the affected versions in the BTS as needed. Regards, Salvatore