Debian Patches

Status for gimp/3.0.4-3+deb13u4

Patch Description Author Forwarded Bugs Origin Last update
plug-ins-dds-fix-12790-for-32-bit.patch plug-ins/dds: fix #12790 for 32-bit
On 32-bit systems the computed linear size can overflow, causing a
crash.
Use a function that checks for overflow when multiplying and return
an error if that fails.
As extra security also update the loop to compute the base offset after
each line of data, and convert to gsize first when computing the
size for g_malloc and memset.

(cherry picked from commit c17b324910204a47828d6fbb542bdcefbd66bcc1)
Jacob Boerema <jgboerema@gmail.com> no 2025-06-12
CVE-2025-10924.patch [PATCH] plug-ins: Fix ZDI-CAN-27836 Alx Sa <cmyk.student@gmail.com> no 2025-09-03
CVE-2025-10923.patch [PATCH] plug-ins: fix ZDI-CAN-27878 Jacob Boerema <jgboerema@gmail.com> no 2025-09-03
CVE-2025-10922.patch [PATCH] plug-ins: fix dicom plug-in ZDI-CAN-27863 Jacob Boerema <jgboerema@gmail.com> no 2025-09-03
CVE-2025-10920.patch [PATCH] plug-ins: Fix ZDI-CAN-27684 Alx Sa <cmyk.student@gmail.com> no 2025-09-03
CVE-2025-10934.patch [PATCH] plug-ins: fix ZDI-CAN-27823 Jacob Boerema <jgboerema@gmail.com> no 2025-09-03
CVE-2025-14424.patch [PATCH] app: fix #15288 crash when loading malformed xcf Jacob Boerema <jgboerema@gmail.com> no 2025-11-13
CVE-2025-14423.patch [PATCH] plug-ins: Fix ZDI-CAN-28311 Alx Sa <cmyk.student@gmail.com> no 2025-11-23
CVE-2025-14422.patch [PATCH] plug-ins: Fix ZDI-CAN-28273 Alx Sa <cmyk.student@gmail.com> no 2025-11-23
CVE-2025-14425.patch [PATCH] plug-ins: Mitigate ZDI-CAN-28248 for JP2 images Alx Sa <cmyk.student@gmail.com> no 2025-11-12

All known versions for source package 'gimp'

Links