ALAS2GIMP-2025-002


Amazon Linux 2 Security Advisory: ALAS2GIMP-2025-002
Advisory Released Date: 2025-07-22
Advisory Updated Date: 2025-07-22
Severity: Low

Issue Overview:

GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability

NOTE: https://www.zerodayinitiative.com/advisories/ZDI-23-1591/
NOTE: https://www.gimp.org/news/2023/11/07/gimp-2-10-36-released/#fixed-vulnerabilities
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/commit/e1bfd87195e4fe60a92df70cde65464d032dd3c1
NOTE: Backport to gimp-2.10: https://gitlab.gnome.org/GNOME/gimp/-/commit/ef12c0a90752a06d4c465a768d052b07f5e8a8a0 (GIMP_2_10_36)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/issues/10071 (restricted)
DEBIANBUG: [1055984] (CVE-2023-44444)


Affected Packages:

gimp


Note:

This advisory is applicable to Amazon Linux 2 - Gimp Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update gimp to update your system.

New Packages:
src:
    gimp-2.8.22-1.amzn2.0.2.src

x86_64:
    gimp-2.8.22-1.amzn2.0.2.x86_64
    gimp-libs-2.8.22-1.amzn2.0.2.x86_64
    gimp-devel-2.8.22-1.amzn2.0.2.x86_64
    gimp-devel-tools-2.8.22-1.amzn2.0.2.x86_64
    gimp-debuginfo-2.8.22-1.amzn2.0.2.x86_64