openSUSE 16: gimp / gimp-devel / gimp-extension-goat-excercises / gimp-lang / etc (openSUSE-SU-2026:21959-1)

high Nessus Plugin ID 350761

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21959-1 advisory.

Changes in gimp:

- CVE-2026-18304: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276233)
- CVE-2026-18301: GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276230)
- CVE-2026-18307: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (bsc#1276236)
- CVE-2026-18303: GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability (bsc#1276232)
- CVE-2026-18308: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276237)
- CVE-2026-18306: GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276235)
- CVE-2026-18305: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276234)
- CVE-2026-18302: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (bsc#1276231)
- CVE-2026-90947: out-of-bounds write in the lighting effects plugin when processing a crafted preset file due to improper validation of the number of light sources (bsc#1280511)
- CVE-2026-90948: When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size (bsc#1280512)
- CVE-2026-92248: When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header (bsc#1280739)

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1276230

https://bugzilla.suse.com/1276231

https://bugzilla.suse.com/1276232

https://bugzilla.suse.com/1276233

https://bugzilla.suse.com/1276234

https://bugzilla.suse.com/1276235

https://bugzilla.suse.com/1276236

https://bugzilla.suse.com/1276237

https://bugzilla.suse.com/1280511

https://bugzilla.suse.com/1280512

https://bugzilla.suse.com/1280739

https://www.suse.com/security/cve/CVE-2026-18301

https://www.suse.com/security/cve/CVE-2026-18302

https://www.suse.com/security/cve/CVE-2026-18303

https://www.suse.com/security/cve/CVE-2026-18304

https://www.suse.com/security/cve/CVE-2026-18305

https://www.suse.com/security/cve/CVE-2026-18306

https://www.suse.com/security/cve/CVE-2026-18307

https://www.suse.com/security/cve/CVE-2026-18308

https://www.suse.com/security/cve/CVE-2026-90947

https://www.suse.com/security/cve/CVE-2026-90948

https://www.suse.com/security/cve/CVE-2026-92248

Plugin Details

Severity: High

ID: 350761

File Name: openSUSE-2026-21959-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/26/2026

Updated: 9/26/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.19

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-92248

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:gimp-devel, p-cpe:/a:novell:opensuse:gimp-extension-goat-excercises, p-cpe:/a:novell:opensuse:gimp-lang, p-cpe:/a:novell:opensuse:gimp-plugin-aa, p-cpe:/a:novell:opensuse:gimp-plugin-python3, p-cpe:/a:novell:opensuse:gimp-vala, p-cpe:/a:novell:opensuse:gimp, p-cpe:/a:novell:opensuse:libgimp-3_0-0, p-cpe:/a:novell:opensuse:libgimpui-3_0-0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/24/2026

Vulnerability Publication Date: 4/30/2026

Reference Information

CVE: CVE-2026-18301, CVE-2026-18302, CVE-2026-18303, CVE-2026-18304, CVE-2026-18305, CVE-2026-18306, CVE-2026-18307, CVE-2026-18308, CVE-2026-90947, CVE-2026-90948, CVE-2026-92248

IAVA: 2026-A-0402-S, 2026-A-1032