CVE-2013-1978
published 2013-12-12CVE-2013-1978: Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to…
PriorityP336medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.19%
89.8th percentile
Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gimp | < gimp 2.8.10-0.1 (bookworm) | gimp 2.8.10-0.1 (bookworm) |
| gimp | gimp | <= 2.6.9 | — |
| gimp | gimp | >= 0 < 2.8.10-0.1 | 2.8.10-0.1 |
| gimp | gimp | >= 0 < 2.8.10-0.1 | 2.8.10-0.1 |
| gimp | gimp | >= 0 < 2.8.10-0.1 | 2.8.10-0.1 |
| gimp | gimp | >= 0 < 2.8.10-0.1 | 2.8.10-0.1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m9mj-2mx7-5fr2: Heap-based buffer overflow in the read_xwd_cols function in file-xwd
ghsa_unreviewed·2022-05-13
CVE-2013-1978 [MEDIUM] CWE-787 GHSA-m9mj-2mx7-5fr2: Heap-based buffer overflow in the read_xwd_cols function in file-xwd
Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.
OSV
CVE-2013-1978: Heap-based buffer overflow in the read_xwd_cols function in file-xwd
osv·2013-12-12·CVSS 6.8
CVE-2013-1978 [MEDIUM] CVE-2013-1978: Heap-based buffer overflow in the read_xwd_cols function in file-xwd
Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.
Ubuntu
GIMP vulnerability
vendor_ubuntu·2013-12-09
CVE-2013-1913 GIMP vulnerability
Title: GIMP vulnerability
Summary: GIMP could be made to crash or run programs as your login if it
opened a specially crafted file.
Murray McAllister discovered that GIMP incorrectly handled malformed XWD
files. If a user were tricked into opening a specially crafted XWD file, an
attacker could cause GIMP to crash, or possibly execute arbitrary code with
the user's privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gimp: XWD plugin color map heap-based buffer overflow
vendor_redhat·2013-12-03·CVSS 6.8
CVE-2013-1978 [MEDIUM] CWE-122 gimp: XWD plugin color map heap-based buffer overflow
gimp: XWD plugin color map heap-based buffer overflow
Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.
Debian
CVE-2013-1978: gimp - Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X ...
vendor_debian·2013·CVSS 6.8
CVE-2013-1978 [MEDIUM] CVE-2013-1978: gimp - Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X ...
Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.
Scope: local
bookworm: resolved (fixed in 2.8.10-0.1)
bullseye: resolved (fixed in 2.8.10-0.1)
forky: resolved (fixed in 2.8.10-0.1)
sid: resolved (fixed in 2.8.10-0.1)
trixie: resolved (fixed in 2.8.10-0.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1913 CVE-2013-1978 gimp: various flaws [fedora-all]
bugzilla·2013-12-03·CVSS 6.8
CVE-2013-1913 [MEDIUM] CVE-2013-1913 CVE-2013-1978 gimp: various flaws [fedora-all]
CVE-2013-1913 CVE-2013-1978 gimp: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple sup
Bugzilla
CVE-2013-1978 gimp: XWD plugin color map heap-based buffer overflow
bugzilla·2013-04-19·CVSS 6.8
CVE-2013-1978 [MEDIUM] CVE-2013-1978 gimp: XWD plugin color map heap-based buffer overflow
CVE-2013-1978 gimp: XWD plugin color map heap-based buffer overflow
Murray McAllister of the Red Hat Security Response Team has discovered a heap-based buffer overflow in the way GIMP, the GNU Image Manipulation Program, performed loading of certain X Window System (XWD) image dumps containing a small number of color map entries but a large number of colors. A remote attacker could provide a specially-crafted XWD format image file that, when processed, would lead to gimp XWD plug-in crash or, potentially, arbitrary code execution with the privileges of the user running the gimp executable.
Discussion:
Created attachment 829128
proposed patch for CVE-2013-1978
The attached patch checks that the number of colormap entries isn't less than the number of colors. While it's not clear if the
http://rhn.redhat.com/errata/RHSA-2013-1778.htmlhttp://www.debian.org/security/2013/dsa-2813http://www.securityfocus.com/bid/64098http://www.ubuntu.com/usn/USN-2051-1https://bugzilla.redhat.com/show_bug.cgi?id=953902https://security.gentoo.org/glsa/201603-01http://rhn.redhat.com/errata/RHSA-2013-1778.htmlhttp://www.debian.org/security/2013/dsa-2813http://www.securityfocus.com/bid/64098http://www.ubuntu.com/usn/USN-2051-1https://bugzilla.redhat.com/show_bug.cgi?id=953902https://security.gentoo.org/glsa/201603-01
2013-12-12
Published