-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-6470-1 [email protected]
https://www.debian.org/security/ Moritz Muehlenhoff
August 27, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : gimp
CVE ID : CVE-2026-18301 CVE-2026-18302 CVE-2026-18303 CVE-2026-18304
CVE-2026-18305 CVE-2026-18306 CVE-2026-18307 CVE-2026-18308
CVE-2026-42170 CVE-2026-58379 CVE-2026-58380 CVE-2026-58381
CVE-2026-58384 CVE-2026-59088 CVE-2026-59090 CVE-2026-66758
CVE-2026-66759
Several vulnerabilities were discovered in GIMP, the GNU Image
Manipulation Program, which could result in denial of service or
potentially the execution of arbitrary code if malformed PSP, TIFF,
DDS, PSD, SGI, FLI, FITS or ICNS files are opened.
For the stable distribution (trixie), these problems have been fixed in
version 3.0.4-3+deb13u10.
We recommend that you upgrade your gimp packages.
For the detailed security status of gimp please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/gimp
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmqP5cAACgkQEMKTtsN8
TjZSoQ//YOsaR1El31lF6YhQN3H13HbgCLmQmmbzljEu3O+MvJLjTLHO3rxhKOCO
zRIo0FzoXvgfp00+TLjnddSBUYr/uFBpAZLBHTjwxtryDxWB7FTOeic0067Akse6
YBn8wJHtsBd6bXs0YEIJLTS9QwlTPxGzswYz2VVdDyx4pzw0nTc3mgYCqbLHW4N0
mR93b8Zt39LjoXt7KAZIQeGvkiWMPG4LGNgY6kZ5I84N1I7WBz+alZvQ50pqY31w
n6aIrGUcmmxE8287AFmrkpmp0bbPXEpLB2FjG6EzMrU6YPhZUQqS6ijFwtq9H1EB
dQbeobjlpnvwDSzygQzwxXJ66O+M4zGGPZmSIc+7h2b6lYare5VDMtt6XYblnBUl
F1ceB0iYMC8q28d0texgPVr9zVoAW5KNll0zczCmrhYeqC/WRzYHBh8vFaioYfTG
/mVsehEhpj2X9E26nZ8RuMi5Chh00ogmLcKam3hN4EWfURLv/O7E2+CzUU4nzphJ
/8+w+JJSg6aX28ARE+njJWssrGNdImdIwV5X+I9g4zI46qtDM/Kykhsm2HDxyGo6
dArBM0/g7GtxaNIdBRJzTFAW/eneaRn+9+89QKKT9Okbf4tn9PZUGV6U4btXhLz1
7dDm4iiLznkoue0eD7H7hK00FRWHZrruWT6f1vfHe/vC5VA3Vqo=
=OcXi
-----END PGP SIGNATURE-----