Public bug reported: The GIMP developers announced at https://www.gimp.org/news/2017/05/11/gimp-2-8-22-released/ that version 2.8.22 finally includes a proper fix for the ancient ICO file import crash CVE-2007-3126. The fix should thus either be back-ported or GIMP bumped to 2.8.22 for supported Ubuntu versions.
** Affects: gimp (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1690544 Title: include proper fix for CVE-2007-3126, released in GIMP 2.8.22 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/gimp/+bug/1690544/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs