Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade gimp-devel-toolsUpgrade gimpUpgrade gimp-help-browserUpgrade gimp-develUpgrade gimp-libs | Dec 1, 2016 | Dec 12, 2013 |
| Debian | — | Upgrade gimp | Jul 30, 2024 | Dec 12, 2013 |
| Gentoo Linux | — | Upgrade media-gfx/gimp. | Oct 30, 2017 | Dec 12, 2013 |
| Oracle_linux | — | Upgrade gimp-libsUpgrade gimp-help-browserUpgrade gimp-devel-toolsUpgrade gimp-develUpgrade gimp | Nov 9, 2016 | Dec 12, 2013 |
| Suse | — | Upgrade gimp-langUpgrade sle-sdk-releaseUpgrade gimpUpgrade gimp-plugins-pythonUpgrade gimp-devel | Feb 13, 2014 | Dec 12, 2013 |
| Ubuntu | — | Upgrade gimp | Nov 8, 2024 | Dec 12, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub