{"id":"MGASA-2013-0365","summary":"Updated gimp package fixes security vulnerabilities","details":"An integer overflow flaw and a heap-based buffer overflow were found in\nthe way GIMP loaded certain X Window System (XWD) image dump files. A\nremote attacker could provide a specially crafted XWD image file that,\nwhen processed, would cause the XWD plug-in to crash or, potentially,\nexecute arbitrary code with the privileges of the user running the GIMP\n(CVE-2013-1913, CVE-2013-1978).\n","modified":"2026-04-16T06:25:22.514619128Z","published":"2013-12-06T22:00:45Z","upstream":["CVE-2013-1913","CVE-2013-1978"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2013-0365.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=11873"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2013-1778.html"}],"affected":[{"package":{"name":"gimp","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/gimp?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.2-3.1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0365.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}