Debian dsa-6470 : gimp - security update

critical Nessus Plugin ID 341055

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 13 host has packages installed that are affected by multiple vulnerabilities as referenced in the dsa-6470 advisory.

- ------------------------------------------------------------------------- Debian Security Advisory DSA-6470-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff August 27, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : gimp CVE ID : CVE-2026-18301 CVE-2026-18302 CVE-2026-18303 CVE-2026-18304 CVE-2026-18305 CVE-2026-18306 CVE-2026-18307 CVE-2026-18308 CVE-2026-42170 CVE-2026-58379 CVE-2026-58380 CVE-2026-58381 CVE-2026-58384 CVE-2026-59088 CVE-2026-59090 CVE-2026-66758 CVE-2026-66759

Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malformed PSP, TIFF, DDS, PSD, SGI, FLI, FITS or ICNS files are opened.

For the stable distribution (trixie), these problems have been fixed in version 3.0.4-3+deb13u10.

We recommend that you upgrade your gimp packages.

For the detailed security status of gimp please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/gimp

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/

Mailing list: [email protected]

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the gimp packages.

See Also

https://packages.debian.org/source/trixie/gimp

https://security-tracker.debian.org/tracker/CVE-2026-18301

https://security-tracker.debian.org/tracker/CVE-2026-18302

https://security-tracker.debian.org/tracker/CVE-2026-18303

https://security-tracker.debian.org/tracker/CVE-2026-18304

https://security-tracker.debian.org/tracker/CVE-2026-18305

https://security-tracker.debian.org/tracker/CVE-2026-18306

https://security-tracker.debian.org/tracker/CVE-2026-18307

https://security-tracker.debian.org/tracker/CVE-2026-18308

https://security-tracker.debian.org/tracker/CVE-2026-42170

https://security-tracker.debian.org/tracker/CVE-2026-58379

https://security-tracker.debian.org/tracker/CVE-2026-58380

https://security-tracker.debian.org/tracker/CVE-2026-58381

https://security-tracker.debian.org/tracker/CVE-2026-58384

https://security-tracker.debian.org/tracker/CVE-2026-59088

https://security-tracker.debian.org/tracker/CVE-2026-59090

https://security-tracker.debian.org/tracker/CVE-2026-66758

https://security-tracker.debian.org/tracker/CVE-2026-66759

https://security-tracker.debian.org/tracker/source-package/gimp

Plugin Details

Severity: Critical

ID: 341055

File Name: debian_DSA-6470.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/27/2026

Updated: 8/27/2026

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.72

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-59090

CVSS v3

Risk Factor: Critical

Base Score: 9.9

Temporal Score: 8.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:13.0, p-cpe:/a:debian:debian_linux:gimp-data, p-cpe:/a:debian:debian_linux:gimp, p-cpe:/a:debian:debian_linux:gir1.2-gimp-3.0, p-cpe:/a:debian:debian_linux:libgimp-3.0-0, p-cpe:/a:debian:debian_linux:libgimp-3.0-bin, p-cpe:/a:debian:debian_linux:libgimp-3.0-dev, p-cpe:/a:debian:debian_linux:libgimp-3.0-doc

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/27/2026

Vulnerability Publication Date: 4/30/2026

Reference Information

CVE: CVE-2026-18301, CVE-2026-18302, CVE-2026-18303, CVE-2026-18304, CVE-2026-18305, CVE-2026-18306, CVE-2026-18307, CVE-2026-18308, CVE-2026-42170, CVE-2026-58379, CVE-2026-58380, CVE-2026-58381, CVE-2026-58384, CVE-2026-59088, CVE-2026-59090, CVE-2026-66758, CVE-2026-66759

IAVA: 2026-A-0402