An integer overflow, leading to heap-based buffer overflow, was found in The Gimp's Personal Computer eXchange (PCX) image file plug-in. A remote attacker could provide a specially-crafted PCX image file, which once opened by a local, unsuspecting user would lead to denial of service (GIMP PCX plug-in crash) or, potentially, arbitrary code execution with the privileges of the user running Gimp.