Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Ubuntu: 2051-1 Moderate: GIMP Crash and Code Execution Threat

ubuntu
Calendar Grey December 9, 2013
Scroller Ubuntu
Security Alert: USN-2051-1 for Ubuntu highlights a vulnerability in GIMP that could lead to crashes or arbitrary code execution via specially crafted images. Ensure your system is protected!
GIMP could be made to crash or run programs as your login if it opened a specially crafted file.

Summary

GIMP could be made to crash or run programs as your login if it

opened a specially crafted file.

Software Description:

- gimp: The GNU Image Manipulation Program

Details:

Murray McAllister discovered that GIMP incorrectly handled malformed XWD

files. If a user were tricked into opening a specially crafted XWD file, an

attacker could cause GIMP to crash, or possibly execute arbitrary code with

the user's privileges.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  gimp                            2.8.6-1ubuntu1.1

Ubuntu 13.04:
  gimp                            2.8.4-1ubuntu1.1

Ubuntu 12.10:
  gimp                            2.8.2-1ubuntu1.2

Ubuntu 12.04 LTS:
  gimp                            2.6.12-1ubuntu1.3

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2051-1

CVE-2013-1913, CVE-2013-1978

Severity
important
Lowest
Low
Medium
High
Critical

December 09, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.