int(3321)

Boletines de Vulnerabilidades


Múltiples desbordamientos de entero en Gimp

Clasificación de la vulnerabilidad

Propiedad Valor
Nivel de Confianza Oficial
Impacto Obtener acceso
Dificultad Experto
Requerimientos del atacante Acceso remoto sin cuenta a un servicio estandar

Información sobre el sistema

Propiedad Valor
Fabricante afectado GNU/Linux
Software afectado Gimp < 2.2.16

Descripción

Se han encontrado múltiples desbordamientos de entero en Gimp. Las vulnerabilidades son descritas a continuación.

- CVE-2006-4519: Se han encontrado múltiples vulnerabilidades del tipo desbordamiento de entero en Gimp en las versiones anteriores a la 2.2.16. La vulnerabilidad reside en un error en los plug-ins para cargar imágenes. Un atacante remoto podría ejecutar código de forma arbitraria mediante valores de longitud especialmente diseñados en los archivos DICOM, PNM, PSD, PSP, sun RAS, XBM y XWD.

- CVE-2007-2949: Se ha encontrado una vulnerabilidad del tipo desbordamiento de entero en Gimp 2.2.15 en el plugin psd.c. La vulnerabilidad reside en un error en la función seek_to_and_unpack_pixeldata. Un atacante remoto podría ejecutar código de forma arbitraria mediante un archivo PSD especialmente diseñado que contenga un valor grande de altura o anchura.

Solución



Actualización de software

Debian

Debian Linux 3.1
Source
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4.dsc
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4.diff.gz
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6.orig.tar.gz
Architecture independent
http://security.debian.org/pool/updates/main/g/gimp/gimp-data_2.2.6-1sarge4_all.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp1.2_2.2.6-1sarge4_all.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-doc_2.2.6-1sarge4_all.deb
Alpha
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_alpha.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_alpha.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_alpha.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_alpha.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_alpha.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_alpha.deb
AMD64
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_amd64.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_amd64.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_amd64.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_amd64.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_amd64.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_amd64.deb
ARM
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_arm.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_arm.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_arm.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_arm.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_arm.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_arm.deb
HP Precision
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_hppa.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_hppa.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_hppa.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_hppa.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_hppa.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_hppa.deb
Intel IA-32
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_i386.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_i386.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_i386.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_i386.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_i386.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_i386.deb
Intel IA-64
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_ia64.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_ia64.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_ia64.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_ia64.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_ia64.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_ia64.deb
Motorola 680x0
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_m68k.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_m68k.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_m68k.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_m68k.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_m68k.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_m68k.deb
PowerPC
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_powerpc.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_powerpc.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_powerpc.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_powerpc.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_powerpc.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_powerpc.deb
IBM S/390
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_s390.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_s390.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_s390.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_s390.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_s390.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_s390.deb
Sun Sparc
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_sparc.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_sparc.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_sparc.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_sparc.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_sparc.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_sparc.deb

Debian Linux 4.0
Source
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4.dsc
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4.diff.gz
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13.orig.tar.gz
Architecture independent
http://security.debian.org/pool/updates/main/g/gimp/gimp-data_2.2.13-1etch4_all.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-doc_2.2.13-1etch4_all.deb
Alpha
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_alpha.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_alpha.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_alpha.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_alpha.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_alpha.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_alpha.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_alpha.deb
AMD64
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_amd64.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_amd64.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_amd64.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_amd64.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_amd64.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_amd64.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_amd64.deb
ARM
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_arm.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_arm.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_arm.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_arm.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_arm.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_arm.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_arm.deb
HP Precision
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_hppa.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_hppa.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_hppa.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_hppa.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_hppa.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_hppa.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_hppa.deb
Intel IA-32
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_i386.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_i386.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_i386.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_i386.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_i386.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_i386.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_i386.deb
Intel IA-64
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_ia64.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_ia64.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_ia64.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_ia64.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_ia64.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_ia64.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_ia64.deb
Little endian MIPS
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_mipsel.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_mipsel.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_mipsel.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_mipsel.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_mipsel.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_mipsel.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_mipsel.deb
PowerPC
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_powerpc.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_powerpc.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_powerpc.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_powerpc.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_powerpc.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_powerpc.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_powerpc.deb
IBM S/390
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_s390.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_s390.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_s390.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_s390.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_s390.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_s390.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_s390.deb
Sun Sparc
http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_sparc.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_sparc.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_sparc.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_sparc.deb
http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_sparc.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_sparc.deb
http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_sparc.deb

Suse Linux
Las actualizaciones pueden descargarse mediante YAST o del servidor FTP oficial de Suse Linux.

Mandriva (MDKSA-2007:170)

Corporate Server 3.0
X86
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/i586/gimp-1.2.5-13.4.C30mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/i586/gimp-doc-1.2.5-13.4.C30mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/i586/gimp-perl-1.2.5-13.4.C30mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/i586/libgimp1.2-1.2.5-13.4.C30mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/i586/libgimp1.2_1-1.2.5-13.4.C30mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/i586/libgimp1.2_1-devel-1.2.5-13.4.C30mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/SRPMS/gimp-1.2.5-13.4.C30mdk.src.rpm
X86_64
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/x86_64/gimp-1.2.5-13.4.C30mdk.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/x86_64/gimp-doc-1.2.5-13.4.C30mdk.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/x86_64/gimp-perl-1.2.5-13.4.C30mdk.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/x86_64/lib64gimp1.2-1.2.5-13.4.C30mdk.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/x86_64/lib64gimp1.2_1-1.2.5-13.4.C30mdk.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/x86_64/lib64gimp1.2_1-devel-1.2.5-13.4.C30mdk.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/SRPMS/gimp-1.2.5-13.4.C30mdk.src.rpm

Mandriva Linux 2007
X86
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/i586/gimp-2.3.10-6.4mdv2007.0.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/i586/gimp-python-2.3.10-6.4mdv2007.0.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/i586/libgimp2.0-devel-2.3.10-6.4mdv2007.0.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/i586/libgimp2.0_0-2.3.10-6.4mdv2007.0.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/SRPMS/gimp-2.3.10-6.4mdv2007.0.src.rpm
X86_64
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/x86_64/gimp-2.3.10-6.4mdv2007.0.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/x86_64/gimp-python-2.3.10-6.4mdv2007.0.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/x86_64/lib64gimp2.0-devel-2.3.10-6.4mdv2007.0.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/x86_64/lib64gimp2.0_0-2.3.10-6.4mdv2007.0.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/SRPMS/gimp-2.3.10-6.4mdv2007.0.src.rpm

Mandriva Linux 2007.1
X86
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/i586/gimp-2.3.14-3.3mdv2007.1.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/i586/gimp-python-2.3.14-3.3mdv2007.1.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/i586/libgimp2.0-devel-2.3.14-3.3mdv2007.1.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/i586/libgimp2.0_0-2.3.14-3.3mdv2007.1.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/SRPMS/gimp-2.3.14-3.3mdv2007.1.src.rpm
X86_64
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/x86_64/gimp-2.3.14-3.3mdv2007.1.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/x86_64/gimp-python-2.3.14-3.3mdv2007.1.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/x86_64/lib64gimp2.0-devel-2.3.14-3.3mdv2007.1.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/x86_64/lib64gimp2.0_0-2.3.14-3.3mdv2007.1.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/SRPMS/gimp-2.3.14-3.3mdv2007.1.src.rpm

Red Hat (RHSA-2007:0513-8)
RHEL Desktop Workstation (v. 5 client)
Red Hat Desktop (v. 3)
Red Hat Desktop (v. 4)
Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux Desktop (v. 5 client)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Enterprise Linux WS (v. 3)
Red Hat Enterprise Linux WS (v. 4)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
https://rhn.redhat.com/

Sun(201320)
Solaris 10 / SPARC / patch 122212-22
Solaris 10 / x86 / patch 122213-22
Solaris 9 / x86 / JDS release 2 / patch 121775-01 o posterior
http://sunsolve.sun.com/pub-cgi/show.pl?target=patchpage

Identificadores estándar

Propiedad Valor
CVE CVE-2006-4519
CVE-2007-2949
BID

Recursos adicionales

Debian Security Advisory (DSA 1335-1)
http://lists.debian.org/debian-security-announce/debian-security-announce-2007/msg00096.html

SUSE Security Summary Report (SUSE-SR:2007:015)
http://www.novell.com/linux/security/advisories/2007_15_sr.html

Mandriva Security Advisory (MDKSA-2007:170)
http://www.mandriva.com/security/advisories?name=MDKSA-2007:170

Red Hat Security Advisory (RHSA-2007:0513-8)
https://rhn.redhat.com/errata/RHSA-2007-0513.html

Sun Alert Notification (103170)
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103170-1

Sun Alert Notification (201320)
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201320-1

Histórico de versiones

Versión Comentario Fecha
1.0 Aviso emitido 2007-07-20
1.1 Aviso emitido por Suse (SUSE-SR:2007:015) 2007-08-07
1.2 Aviso emitido por Mandriva (MDKSA-2007:170) 2007-08-24
1.3 Aviso emitido por Red Hat (RHSA-2007:0513-8) 2007-09-26
1.4 Aviso emitido por Sun (103170) 2007-12-21
1.5 Aviso actualizado por Sun (201320) 2008-09-18

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT