------------------------------------------------------------------------- Debian LTS Advisory DLA-4362-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Markus Koschany November 03, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : gimp Version : 2.10.22-4+deb11u4 CVE ID : CVE-2025-10934 Debian Bug : 1119661 GIMP, the GNU Image Manipulation Program, is vulnerable to a heap-based buffer overflow when parsing XWD files. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP and requires the target to visit a malicious page or open a malicious file. For Debian 11 bullseye, this problem has been fixed in version 2.10.22-4+deb11u4. We recommend that you upgrade your gimp packages. For the detailed security status of gimp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/gimp Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment:
signature.asc
Description: This is a digitally signed message part