CVE-2013-1913

Description

Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large color entries value in an X Window System (XWD) image dump.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.017

Associated Vulnerability

VulnerabilityOS Platform
Upgrade gimp 2.6.9 to latest versionWindows
Multiple Vulnerabilities are affected in GIMP 2.6.7Windows
Multiple Vulnerabilities are affected in GIMP 2.6.8Windows
Multiple Vulnerabilities are affected in GIMP 2.6.1Windows
Multiple Vulnerabilities are affected in GIMP 2.6.6Windows
Multiple Vulnerabilities are affected in GIMP 2.6.0Windows
Multiple Vulnerabilities are affected in GIMP 2.6.2Windows
Multiple Vulnerabilities are affected in GIMP 2.6.3Windows
Multiple Vulnerabilities are affected in GIMP 2.6.4Windows
Multiple Vulnerabilities are affected in GIMP 2.6.5Windows
Multiple Vulnerabilities are affected in GIMP 2.6.9Windows
(RHSA-2013:1778) Moderate: gimp security update gimp-2.2.13-3.el5_10.i386.rpmLinux
(RHSA-2013:1778) Moderate: gimp security update gimp-2.2.13-3.el5_10.x86_64.rpmLinux
(RHSA-2013:1778) Moderate: gimp security update gimp-2.6.9-6.el6_5.i686.rpmLinux
(RHSA-2013:1778) Moderate: gimp security update gimp-2.6.9-6.el6_5.x86_64.rpmLinux
(RHSA-2013:1778) Moderate: gimp security update gimp-devel-2.2.13-3.el5_10.i386.rpmLinux
(RHSA-2013:1778) Moderate: gimp security update gimp-devel-2.2.13-3.el5_10.x86_64.rpmLinux
(RHSA-2013:1778) Moderate: gimp security update gimp-devel-2.6.9-6.el6_5.i686.rpmLinux
(RHSA-2013:1778) Moderate: gimp security update gimp-devel-2.6.9-6.el6_5.x86_64.rpmLinux
(RHSA-2013:1778) Moderate: gimp security update gimp-devel-tools-2.6.9-6.el6_5.i686.rpmLinux
(RHSA-2013:1778) Moderate: gimp security update gimp-devel-tools-2.6.9-6.el6_5.x86_64.rpmLinux
(RHSA-2013:1778) Moderate: gimp security update gimp-help-browser-2.6.9-6.el6_5.i686.rpmLinux
(RHSA-2013:1778) Moderate: gimp security update gimp-help-browser-2.6.9-6.el6_5.x86_64.rpmLinux
(RHSA-2013:1778) Moderate: gimp security update gimp-libs-2.2.13-3.el5_10.i386.rpmLinux
(RHSA-2013:1778) Moderate: gimp security update gimp-libs-2.2.13-3.el5_10.x86_64.rpmLinux
(RHSA-2013:1778) Moderate: gimp security update gimp-libs-2.6.9-6.el6_5.i686.rpmLinux
(RHSA-2013:1778) Moderate: gimp security update gimp-libs-2.6.9-6.el6_5.x86_64.rpmLinux
Gimp-help update (ELSA-2016-2589) gimp-help-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-ca update (ELSA-2016-2589) gimp-help-ca-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-da update (ELSA-2016-2589) gimp-help-da-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-de update (ELSA-2016-2589) gimp-help-de-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-el update (ELSA-2016-2589) gimp-help-el-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-en_GB update (ELSA-2016-2589) gimp-help-en_GB-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-es update (ELSA-2016-2589) gimp-help-es-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-fr update (ELSA-2016-2589) gimp-help-fr-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-it update (ELSA-2016-2589) gimp-help-it-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-ja update (ELSA-2016-2589) gimp-help-ja-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-ko update (ELSA-2016-2589) gimp-help-ko-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-nl update (ELSA-2016-2589) gimp-help-nl-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-nn update (ELSA-2016-2589) gimp-help-nn-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-pt_BR update (ELSA-2016-2589) gimp-help-pt_BR-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-ru update (ELSA-2016-2589) gimp-help-ru-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-sl update (ELSA-2016-2589) gimp-help-sl-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-sv update (ELSA-2016-2589) gimp-help-sv-2.8.2-1.el7.noarch.rpmLinux
Gimp-help-zh_CN update (ELSA-2016-2589) gimp-help-zh_CN-2.8.2-1.el7.noarch.rpmLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234