First published: Fri Apr 19 2013(Updated: )
Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GIMP | <=2.6.9 | |
GNOME libraries | <=2.24.0 | |
Red Hat Enterprise Linux | =5.0 | |
Red Hat Enterprise Linux | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1978 is rated as a high severity vulnerability due to the potential for arbitrary code execution and denial of service.
To fix CVE-2013-1978, update GIMP to version 2.8.0 or later.
Exploitation of CVE-2013-1978 can lead to a denial of service and the execution of arbitrary code.
GIMP versions prior to 2.6.9 are affected by CVE-2013-1978.
Currently, the best workaround for CVE-2013-1978 is to disable the XWD plugin in GIMP until an update is applied.