6.8
CVSSv2

CVE-2013-1978

Published: 12/12/2013 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and previous versions allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gimp gimp

redhat enterprise linux 6.0

redhat enterprise linux 5.0

Vendor Advisories

Synopsis Moderate: gimp security update Type/Severity Security Advisory: Moderate Topic Updated gimp packages that fix three security issues are now available forRed Hat Enterprise Linux 5 and 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability ...
GIMP could be made to crash or run programs as your login if it opened a specially crafted file ...
Debian Bug report logs - #731305 gimp: CVE-2013-1913 CVE-2013-1978 Package: gimp; Maintainer for gimp is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Source for gimp is src:gimp (PTS, buildd, popcon) Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 4 Dec 2013 06:15:02 UTC ...
Murray McAllister discovered multiple integer and buffer overflows in the XWD plugin in Gimp, which can result in the execution of arbitrary code For the oldstable distribution (squeeze), these problems have been fixed in version 2610-1+squeeze4 This update also fixes CVE-2012-3403, CVE-2012-3481 and CVE-2012-5576 For the stable distribution ( ...
Heap-based buffer overflow in the read_xwd_cols function in file-xwdc in the X Window Dump (XWD) plug-in in GIMP 269 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries ...