CVE-2013-1978

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
12/12/2013
Last modified:
11/04/2025

Description

Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gimp:gimp:*:*:*:*:*:*:*:* 2.6.9 (including)
cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:* 2.24.0 (including)
cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*