Bug 30496 - gimp, gimp3 new security issue CVE-2022-30067
Summary: gimp, gimp3 new security issue CVE-2022-30067
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-05-31 22:52 CEST by David Walser
Modified: 2022-06-03 19:16 CEST (History)
6 users (show)

See Also:
Source RPM: gimp-2.10.24-1.mga8.src.rpm
CVE: CVE-2022-30067
Status comment:


Attachments
crafted XCF file (644 bytes, image/x-xcf)
2022-06-01 16:19 CEST, Herman Viaene
Details

Description David Walser 2022-05-31 22:52:57 CEST
SUSE has issued an advisory today (May 31):
https://lists.suse.com/pipermail/sle-security-updates/2022-May/011204.html

Mageia 8 is also affected.
David Walser 2022-05-31 22:53:19 CEST

Whiteboard: (none) => MGA8TOO

Comment 1 Lewis Smith 2022-06-01 07:40:38 CEST
Assigning to Stig who has maintained Gimp previously.
CC'ing tv for the Gimp3 bit.

Assignee: bugsquad => smelror
CC: (none) => thierry.vignaud

Comment 2 Stig-Ørjan Smelror 2022-06-01 08:58:48 CEST
Updates pushed to Cauldron for both 2.10 and 2.99(3.x)

Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8
Source RPM: gimp-2.10.30-3.mga9.src.rpm, gimp3-2.99.10-2.mga9.src.rpm => gimp-2.10.24-1.mga8.src.rpm

Comment 3 Stig-Ørjan Smelror 2022-06-01 12:37:21 CEST
Advisory
========

GIMP has been updated with an upstream fix for CVE-2022-30067.

CVE-2022-30067: GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash.


References
==========
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30067
https://lists.suse.com/pipermail/sle-security-updates/2022-May/011204.html


Files
=====

Uploaded to core/updates_testing

lib64gimp2.0_0-2.10.24-1.1.mga8
lib64gimp2.0-devel-2.10.24-1.1.mga8
gimp-2.10.24-1.1.mga8

from gimp-2.10.24-1.1.mga8.src.rpm

CVE: (none) => CVE-2022-30067
Assignee: smelror => qa-bugs

Comment 4 Jose Manuel López 2022-06-01 13:06:50 CEST
Hi, in this bug I updated Gimp to 2.10.30 for Mageia 8. If someone can upload this to testing repositories, we update Gimp to 2.10.30, with this bugfixed.

https://bugs.mageia.org/show_bug.cgi?id=29473

Greetings

CC: (none) => joselp

Comment 5 Herman Viaene 2022-06-01 16:18:48 CEST
MGA8-64 Plasma on Lenovo B50 in Dutch
No installaion issues.
Tied a few color and size operations: works OK.
Found crafted file in https://gitlab.gnome.org/GNOME/gimp/-/issues/8120. This version of GIMP rejects this file as being incomplete or damaged.
I guess that demonstrates the fix.
I will upload the XCF file.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => herman.viaene

Comment 6 Herman Viaene 2022-06-01 16:19:51 CEST
Created attachment 13287 [details]
crafted XCF file
Comment 7 Thomas Andrews 2022-06-02 00:44:45 CEST
I downloaded the "crafted XCF" file and attempted to load it into Gimp before updating. All it did, visibly anyway, is crash without any notice. 

No installation issues with the update. Ran the "crafted XCF" file again, and this time there was a notice that the file was corrupt, but no crash. So, as Herman says, that seems to demonstrate the fix.

Loaded an XCF file that I have been working with recently, a color-coded map of our farm showing what crops we have planted or will be planting where, with labels showing field size. It is a complex image, with over 70 layers. When finished, it will be printed and turned in to the USDA. For this session, I made some corrections to the file, editing labels, redrawing some spots to closer represent reality, then saving the image. No issues to report, so confirming the OK.

CC: (none) => andrewsfarm

Comment 8 Thomas Andrews 2022-06-02 00:57:52 CEST
(In reply to Jose Manuel López from comment #4)
> Hi, in this bug I updated Gimp to 2.10.30 for Mageia 8. If someone can
> upload this to testing repositories, we update Gimp to 2.10.30, with this
> bugfixed.
> 
> https://bugs.mageia.org/show_bug.cgi?id=29473
> 
Jose, the proposed advisory for this bug says that Gimp 2.10.30 is vulnerable to this issue. I see nothing in Bug 29473 that shows that this particular issue was addressed in the 2.10.30 that you built. So, I'm not going to hold this back at this time.

Validating this update, to get this fix out there. Advisory in Comment 3.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Dave Hodgins 2022-06-02 22:36:44 CEST

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 9 Mageia Robot 2022-06-03 19:16:32 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0219.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.