Ubuntu Security Notice 480-1 – Stefan Cornelius discovered that Gimp could miscalculate the size of heap buffers when processing PSD images. By tricking a user into opening a specially crafted PSD file with Gimp, an attacker could exploit this to execute arbitrary code with the user’s privileges.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/57503/USN-480-1.txt
Source: https://packetstormsecurity.com/files/57503/Ubuntu-Security-Notice-480-1.html

