PT-2013-1157 · Gnu+3 · Gimp+3

Published

2013-12-03

·

Updated

2023-02-13

·

CVE-2013-1913

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GIMP versions 2.6.9 and earlier
Description The issue is related to an integer overflow in the load image function in the X Window Dump (XWD) plug-in. This can be triggered by a large color entries value in an X Window System (XWD) image dump, potentially allowing remote attackers to cause a denial of service (crash) and possibly execute arbitrary code. The vulnerability can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For GIMP versions 2.6.9 and earlier, consider updating to a version that uses glib 2.24 or later to mitigate the risk. As a temporary workaround, consider restricting the use of the XWD plug-in or avoiding the processing of untrusted XWD image dumps until a patch is available.

Fix

DoS

Integer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2015-06187
BDU:2015-08911
CESA-2013_1778
CVE-2013-1913
DSA-2813-1
MGASA-2013-0365
RHSA-2013:1778
RHSA-2013_1778

Affected Products

Centos
Gimp
Red Hat
Suse