Description
GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated by the gimp_write_and_read_file function in app/tests/test-xcf.c. This might be leveraged by attackers to overwrite files or read file content that was intended to be private.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 12 | | =2.10.34-1 || =2.10.34-1+deb12u1 || =2.10.34-1+deb12u10 || =2.10.34-1+deb12u2 || =2.10.34-1+deb12u3 || =2.10.34-1+deb12u4 || =2.10.34-1+deb12u5 || =2.10.34-1+deb12u6 || =2.10.34-1+deb12u7 || =2.10.34-1+deb12u8 || =2.10.34-1+deb12u9 || =2.10.36-1 || =2.10.36-2 || =2.10.36-3 || =2.10.38-1 || =2.10.38-2 || =2.99.10-1 || =2.99.12-1 || =2.99.12-2 || =2.99.14-1 || =2.99.14-2 || =2.99.16-1 || =2.99.16-2 || =2.99.18-1 || =3.0.0-1 || =3.0.0-2 || =3.0.0~rc1-1 || =3.0.0~rc1-3 || =3.0.0~rc1-4 || =3.0.0~rc2-1 || =3.0.0~rc3-1 || =3.0.2-1 || =3.0.2-2 || =3.0.2-3 || =3.0.2-3.1 || =3.0.4-1 || =3.0.4-2 || =3.0.4-3 || =3.0.4-4 || =3.0.4-5 || =3.0.4-6 || =3.0.4-6.1 || =3.0.4-6.2 || =3.0.6-1 || =3.2.0-1 || =3.2.0~rc2-1 || =3.2.0~rc2-2 || =3.2.0~rc2-3 || =3.2.0~rc2-3.1 || =3.2.0~rc2-3.2 || =3.2.0~rc2-3.3 || =3.2.0~rc3-1 || =3.2.2-1 || =3.2.4-1 | - |
 debian 14 | | | 3.0.0~rc1-4 |
 debian 11 | | =2.10.22-4 || =2.10.22-4+deb11u1 || =2.10.22-4+deb11u2 || =2.10.22-4+deb11u3 || =2.10.22-4+deb11u4 || =2.10.22-4+deb11u5 || =2.10.22-4+deb11u6 || =2.10.22-4+deb11u7 || =2.10.22-4+deb11u8 || =2.10.24-1 || =2.10.24-2 || =2.10.26-1 || =2.10.28-1 || =2.10.30-1 || =2.10.32-1 || =2.10.34-1 || =2.10.36-1 || =2.10.36-2 || =2.10.36-3 || =2.10.38-1 || =2.10.38-2 || =2.99.10-1 || =2.99.12-1 || =2.99.12-2 || =2.99.14-1 || =2.99.14-2 || =2.99.16-1 || =2.99.16-2 || =2.99.18-1 || =3.0.0-1 || =3.0.0-2 || =3.0.0~rc1-1 || =3.0.0~rc1-3 || =3.0.0~rc1-4 || =3.0.0~rc2-1 || =3.0.0~rc3-1 || =3.0.2-1 || =3.0.2-2 || =3.0.2-3 || =3.0.2-3.1 || =3.0.4-1 || =3.0.4-2 || =3.0.4-3 || =3.0.4-4 || =3.0.4-5 || =3.0.4-6 || =3.0.4-6.1 || =3.0.4-6.2 || =3.0.6-1 || =3.2.0-1 || =3.2.0~rc2-1 || =3.2.0~rc2-2 || =3.2.0~rc2-3 || =3.2.0~rc2-3.1 || =3.2.0~rc2-3.2 || =3.2.0~rc2-3.3 || =3.2.0~rc3-1 || =3.2.2-1 || =3.2.4-1 | - |
 debian 13 | | | 3.0.0~rc1-4 |
 rpm rhel8 | | - | - |
 rpm rhel7 | | - | - |