cbcvebase.
CVE-2013-1953
published 2013-12-09

CVE-2013-1953: Integer underflow in the input_bmp_reader function in input-bmp.c in AutoTrace 0.31.1 allows context-dependent attackers to have an unspecified impact via a…

PriorityP427medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.73%
75.1th percentile
Integer underflow in the input_bmp_reader function in input-bmp.c in AutoTrace 0.31.1 allows context-dependent attackers to have an unspecified impact via a small value in the biSize field in the header of a BMP file, which triggers a buffer overflow.

Affected

6 ranges
VendorProductVersion rangeFixed in
autotrace_projectautotrace
debiangimp< gimp 2.6.10-1 (bookworm)gimp 2.6.10-1 (bookworm)
gimpgimp>= 0 < 2.6.10-12.6.10-1
gimpgimp>= 0 < 2.6.10-12.6.10-1
gimpgimp>= 0 < 2.6.10-12.6.10-1
gimpgimp>= 0 < 2.6.10-12.6.10-1

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.