Summary: | <media-gfx/gimp-2.10.32: memory exhaustion via crafted file | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | IN_PROGRESS --- | ||
Severity: | minor | CC: | proxy-maint, torokhov-s-a |
Priority: | Normal | Keywords: | PullRequest |
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://gitlab.gnome.org/GNOME/gimp/-/issues/8120 | ||
See Also: |
https://github.com/gentoo/gentoo/pull/25757 https://github.com/gentoo/gentoo/pull/26355 |
||
Whiteboard: | B3 [glsa?] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 856790 | ||
Bug Blocks: |
Description
John Helmert III
2022-05-18 17:47:36 UTC
Pull Request updated with gimp-2.10.32 version bump instead of patched version of gimp-2.10.30. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=7d2e5965d2cee1eb84e26896fec3321e2d195527 commit 7d2e5965d2cee1eb84e26896fec3321e2d195527 Author: Sergey Torokhov <torokhov-s-a@yandex.ru> AuthorDate: 2022-06-04 20:47:53 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2022-06-15 20:56:26 +0000 media-gfx/gimp: 2.10.32 version bump, fix CVE-2022-30067 Bug: https://bugs.gentoo.org/845402 Signed-off-by: Sergey Torokhov <torokhov-s-a@yandex.ru> Closes: https://github.com/gentoo/gentoo/pull/25757 Signed-off-by: Sam James <sam@gentoo.org> media-gfx/gimp/Manifest | 1 + media-gfx/gimp/gimp-2.10.32.ebuild | 210 +++++++++++++++++++++++++++++++++++++ 2 files changed, 211 insertions(+) Stable request: https://bugs.gentoo.org/856790 Thanks! In the future you can just add the security bugs to stablereqs in the "blocks" field. Please cleanup The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=180e767499a9434ebbee66cab692bdc5c0278f98 commit 180e767499a9434ebbee66cab692bdc5c0278f98 Author: Sergey Torokhov <torokhov-s-a@yandex.ru> AuthorDate: 2022-07-11 21:24:09 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2022-07-11 22:48:01 +0000 media-gfx/gimp: cleanup CVEs affected 2.10.28, 2.10.30 Bug: https://bugs.gentoo.org/845402 Bug: https://bugs.gentoo.org/856283 Signed-off-by: Sergey Torokhov <torokhov-s-a@yandex.ru> Signed-off-by: John Helmert III <ajak@gentoo.org> media-gfx/gimp/Manifest | 2 - media-gfx/gimp/gimp-2.10.28-r1.ebuild | 211 ---------------------------------- media-gfx/gimp/gimp-2.10.30.ebuild | 211 ---------------------------------- 3 files changed, 424 deletions(-) Thanks! |