An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS).
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade gimpUpgrade gimp-libs | Nov 21, 2022 | Jun 24, 2022 |
| Centos_linux | — | Upgrade gimp-libsUpgrade gimp-debuginfoUpgrade gimpUpgrade gimp-devel-tools-debuginfoUpgrade gimp-debugsourceUpgrade gimp-libs-debuginfo | Nov 16, 2022 | Jun 24, 2022 |
| Debian | — | Upgrade gimp | Jul 30, 2024 | Jun 24, 2022 |
| Gentoo Linux | — | Upgrade media-gfx/gimp. | Jan 20, 2025 | Jun 24, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade gimpUpgrade gimp-libs | Oct 11, 2022 | Jun 24, 2022 |
| Oracle_linux | — | Upgrade gimp-libsUpgrade gimp | Nov 22, 2022 | Jun 3, 2022 |
| Redhat_linux | — | Upgrade gimp-debuginfoUpgrade gimp-devel-tools-debuginfoUpgrade gimpUpgrade gimp-libsUpgrade gimp-libs-debuginfoUpgrade gimp-debugsourceNo solution exists | Nov 16, 2022 | Jun 24, 2022 |
| Rocky_linux | — | Upgrade gimp-libs-debuginfoUpgrade gimpUpgrade gimp-libsUpgrade gimp-debuginfoUpgrade gimp-debugsource | Mar 12, 2024 | Jun 24, 2022 |
| Suse | — | Upgrade gimp-langUpgrade gimp-plugin-aaUpgrade gimp-plugins-pythonUpgrade libgimpui-2_0-0Upgrade libgimp-2_0-0Upgrade gimpUpgrade libgimp-2_0-0-32bitUpgrade libgimpui-2_0-0-32bitUpgrade gimp-devel | Oct 26, 2022 | Jun 24, 2022 |
| Ubuntu | — | Upgrade gimp | Nov 30, 2023 | Jun 24, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub