Release date:
Updated on:
Affected Systems:
GIMP 2.8.10
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-1978
GIMP is short for GNU Image Manipulation Program (GNU Image Processing Program) and is a cross-platform Image processing software.
The "load_image ()" function (plug-ins/common/file-xwd.c) of GIMP 2.8.10 has a boundary error in implementation, remote attackers can exploit this vulnerability to send specially crafted XWD files, which can cause heap buffer overflow.
<* Source: Murray McAllister
Link: http://secunia.com/advisories/55908/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
GIMP
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.gimp.org/
Https://git.gnome.org/browse/gimp/commit? Id = 23f685931e5f000dd033a45c60c1e60d7f78caf4
Install the official version of GIMP 12.04 in Ubuntu 2.8
Ubuntu 2.8 wallpaper created by GIMP 12.04