CVE-2013-1913

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
12/12/2013
Last modified:
11/04/2025

Description

Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large color entries value in an X Window System (XWD) image dump.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gimp:gimp:*:*:*:*:*:*:*:* 2.6.9 (including)
cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:* 2.24.0 (including)
cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*