Xenial/16.04: GIMP needs a security update - unfixed issues (CVE-2017: 17784-17789).
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
gimp (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Xenial |
New
|
Undecided
|
Unassigned |
Bug Description
Hello.
GIMP package ('Universe/
Anyway, it looks this way: in "Trusty" the available version is: '2.8.10-0ubuntu1.2' (please see [1]). "Bionic" has '2.8.20-1.1' version (please see [2]). Both Releases contains fixes for mentioned security issues: CVE-2017-* etc. However, GIMP version in "Xenial" is '2.8.16-1ubuntu1.1' and does not contain any security updates from 2017. (The last one is from Thu, 30 Jun 2016.; please see [3]).
Security updates with fixes for mentioned CVE's (please compare changes in 1. and 2. with 3.) were released on Thu., 18 Jan 2018 - for "Trusty" and Tue., 26 Dec 2017 - for "Bionic". In "Xenial", the last security update is from Thu., 30 Jun 2016 (fix for CVE-2016-4994) and there is no further updates!
Here is a CVE list of security issues not fixed in "Xenial", but in "Trusty" and "Bionic" etc.:
1/ CVE-2017-17784: Heap-buffer over-read in load_image file-gbr.c
2/ CVE-2017-17785: Heap-based buffer overflow in fli_read_brun function
3/ CVE-2017-17786: Out of bounds read
4/ CVE-2017-17787: Heap-based buffer over-read in read_creator_block
5/ CVE-2017-17788: Stack-based buffer over-read in xcf_load_stream
6/ CVE-2017-17789: Heap-based buffer overflow in read_channel_data
And the most important thing: if User had installed GIMP package in "Xenial" Release, he is affected - since one year, at least - because of a vulnerable version. Security issues, mentioned above, are from 2017. So, maybe it's a good opportunity to update GIMP to v2.10.2 version, released on 20., May 2018? (Version 2.8.X is very outdated).
I wanted to send an email to Mr Marc Deslauriers, because he made the last security update for GIMP in "Xenial" (fix for CVE-2016-4994). But I decided to report a bug on Launchpad. I hope that it's an acceptable way. If not, I'm sorry.
By the way: similar problems with unfixed security issues, can be found e.g. in Audacious and Parole packages. But that's a different story, completely different story...
Thanks, best regards.
_______
1. http://
2. http://
3. http://
description: | updated |
description: | updated |
summary: |
- Xenial/16.04: GIMP needs a security update - unfixed issues - (CVE-2017-*). + Xenial/16.04: GIMP needs a security update - unfixed issues (CVE-2017: + 17784-17789). |
information type: | Public → Public Security |
Changed in gimp (Ubuntu): | |
status: | Confirmed → Incomplete |
Changed in gimp (Ubuntu Xenial): | |
status: | New → Confirmed |
Changed in gimp (Ubuntu Xenial): | |
status: | Confirmed → New |
information type: | Public Security → Private Security |
information type: | Private Security → Public Security |
no longer affects: | gimp (Ubuntu Artful) |
Changed in gimp (Ubuntu): | |
status: | Incomplete → Fix Released |
tags: |
added: upgrade-xenial-version removed: upgrade-software-version |
I don't know why 'fglrx-installer' was chosen as an affected package. During creating a report I've chosen 'gimp' package.