Monday, December 9, 2013

[USN-2051-1] GIMP vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSpcK9AAoJEGVp2FWnRL6TNxEQAJQCRtjlCH/q1zGoHpJiTP47
tuzjCd3qwEqOV3HD2pNbowoS1kxFeRoUjl3MaluhQ0tXUugBtCVKtAHbdr6D9WVC
e3Ez95J4aBdqevwYDOoFxYgUZWyMLYIZUgcyBhoDmozRcYAlyFZrhEhjOsG9UAMb
cEomaSQuI+sODVKtB2je8hpJd002cewM3Xq5GeCNSaztNuZc3QmvZoi2e6BAcIB0
vtzz48BvHB+zs+v0cNdhMpYBYXedszJrClDb8kcjbYqDZpldibjQH0ptr6BlIHWN
pbhCNl0ujfh43V4x5VBxp9FsD6J+zooBWsWKj00bRcRFrCl7YWw/MjY7PxstsrFJ
mZ1i9nDl3ZYQ8bYagO9ZlVN9D2zX/OAPwbtmCwirijF5Iv3oVjb6VL0UgxMh91H3
OOwUgLLbKOm5w4Bejr7+8F/eanR0vLmVYo35oNRHmDI8wGCFAR5oxvhk4euzdfah
6BFIpNbe6ep02Y1uV1jm9lqWKAgZsoRCkgVL9R9WzM9q28xg9jGufozpAKDRuBKL
mrD8p31fziHhxTa84OFaPYO1HIl6DcRmXF/XCs1/10AuxmIIvWmvqV3c6bcK/UpM
uhTigOJI3y9bnZCLg/GI1BV9tgGN3wRYIVLEAlgLkDR3X1SBV9c/RbN6fJf80pSW
Qjn9fSA6fA5qoijAGcOD
=UVD4
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2051-1
December 09, 2013

gimp vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.10
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS

Summary:

GIMP could be made to crash or run programs as your login if it
opened a specially crafted file.

Software Description:
- gimp: The GNU Image Manipulation Program

Details:

Murray McAllister discovered that GIMP incorrectly handled malformed XWD
files. If a user were tricked into opening a specially crafted XWD file, an
attacker could cause GIMP to crash, or possibly execute arbitrary code with
the user's privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
gimp 2.8.6-1ubuntu1.1

Ubuntu 13.04:
gimp 2.8.4-1ubuntu1.1

Ubuntu 12.10:
gimp 2.8.2-1ubuntu1.2

Ubuntu 12.04 LTS:
gimp 2.6.12-1ubuntu1.3

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2051-1
CVE-2013-1913, CVE-2013-1978

Package Information:
https://launchpad.net/ubuntu/+source/gimp/2.8.6-1ubuntu1.1
https://launchpad.net/ubuntu/+source/gimp/2.8.4-1ubuntu1.1
https://launchpad.net/ubuntu/+source/gimp/2.8.2-1ubuntu1.2
https://launchpad.net/ubuntu/+source/gimp/2.6.12-1ubuntu1.3

No comments:

Post a Comment