CVE-2013-1913
published 2013-12-12CVE-2013-1913: Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.07%
89.5th percentile
Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large color entries value in an X Window System (XWD) image dump.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gimp | < gimp 2.8.10-0.1 (bookworm) | gimp 2.8.10-0.1 (bookworm) |
| gimp | gimp | <= 2.6.9 | — |
| gimp | gimp | >= 0 < 2.8.10-0.1 | 2.8.10-0.1 |
| gimp | gimp | >= 0 < 2.8.10-0.1 | 2.8.10-0.1 |
| gimp | gimp | >= 0 < 2.8.10-0.1 | 2.8.10-0.1 |
| gimp | gimp | >= 0 < 2.8.10-0.1 | 2.8.10-0.1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v6j5-c6r3-rmxr: Integer overflow in the load_image function in file-xwd
ghsa_unreviewed·2022-05-13
CVE-2013-1913 [MEDIUM] CWE-190 GHSA-v6j5-c6r3-rmxr: Integer overflow in the load_image function in file-xwd
Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large color entries value in an X Window System (XWD) image dump.
OSV
CVE-2013-1913: Integer overflow in the load_image function in file-xwd
osv·2013-12-12·CVSS 6.8
CVE-2013-1913 [MEDIUM] CVE-2013-1913: Integer overflow in the load_image function in file-xwd
Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large color entries value in an X Window System (XWD) image dump.
Ubuntu
GIMP vulnerability
vendor_ubuntu·2013-12-09
CVE-2013-1913 GIMP vulnerability
Title: GIMP vulnerability
Summary: GIMP could be made to crash or run programs as your login if it
opened a specially crafted file.
Murray McAllister discovered that GIMP incorrectly handled malformed XWD
files. If a user were tricked into opening a specially crafted XWD file, an
attacker could cause GIMP to crash, or possibly execute arbitrary code with
the user's privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gimp: xwd plugin g_new() integer overflow
vendor_redhat·2013-12-03·CVSS 6.8
CVE-2013-1913 [MEDIUM] CWE-190 gimp: xwd plugin g_new() integer overflow
gimp: xwd plugin g_new() integer overflow
Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large color entries value in an X Window System (XWD) image dump.
Package: gimp (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-1913: gimp - Integer overflow in the load_image function in file-xwd.c in the X Window Dump (...
vendor_debian·2013·CVSS 6.8
CVE-2013-1913 [MEDIUM] CVE-2013-1913: gimp - Integer overflow in the load_image function in file-xwd.c in the X Window Dump (...
Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large color entries value in an X Window System (XWD) image dump.
Scope: local
bookworm: resolved (fixed in 2.8.10-0.1)
bullseye: resolved (fixed in 2.8.10-0.1)
forky: resolved (fixed in 2.8.10-0.1)
sid: resolved (fixed in 2.8.10-0.1)
trixie: resolved (fixed in 2.8.10-0.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1913 CVE-2013-1978 gimp: various flaws [fedora-all]
bugzilla·2013-12-03·CVSS 6.8
CVE-2013-1913 [MEDIUM] CVE-2013-1913 CVE-2013-1978 gimp: various flaws [fedora-all]
CVE-2013-1913 CVE-2013-1978 gimp: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple sup
Bugzilla
CVE-2013-1913 gimp: xwd plugin g_new() integer overflow
bugzilla·2013-04-03·CVSS 6.8
CVE-2013-1913 [MEDIUM] CVE-2013-1913 gimp: xwd plugin g_new() integer overflow
CVE-2013-1913 gimp: xwd plugin g_new() integer overflow
Murray McAllister of the Red Hat Security Response Team has discovered an integer overflow in the way GIMP, the GNU Image Manipulation Program, performed loading of certain X Window System (XWD) image dumps containing large a color entries value. A remote attacker could provide a specially-crafted XWD format image file that, when processed, would lead to gimp XWD plug-in crash or, potentially, arbitrary code execution with the privileges of the user running the gimp executable.
Discussion:
Created attachment 829636
updated patch for CVE-2013-1913
---
This problem is in load_image() in file-xwd.c. xwdcolmap (buffer to store color map) is allocated using glib's g_new using l_colormap_entries value from the image header, which wasn'
http://rhn.redhat.com/errata/RHSA-2013-1778.htmlhttp://www.debian.org/security/2013/dsa-2813http://www.securityfocus.com/bid/64105http://www.ubuntu.com/usn/USN-2051-1https://bugzilla.redhat.com/show_bug.cgi?id=947868https://security.gentoo.org/glsa/201603-01http://rhn.redhat.com/errata/RHSA-2013-1778.htmlhttp://www.debian.org/security/2013/dsa-2813http://www.securityfocus.com/bid/64105http://www.ubuntu.com/usn/USN-2051-1https://bugzilla.redhat.com/show_bug.cgi?id=947868https://security.gentoo.org/glsa/201603-01
2013-12-12
Published