PT-2012-4243 · Gnu+1 · Gimp+1
Joseph Sheridan
·
Published
2012-07-12
·
Updated
2022-02-07
·
CVE-2012-2763
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GIMP versions 2.6.12 and earlier
Description
The issue is related to a buffer overflow in the readstr upto function, which can be exploited by remote attackers to execute arbitrary code. This is achieved by sending a long string in a command to the script-fu server.
Recommendations
For GIMP versions 2.6.12 and earlier, update to a version that contains a fix for this issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gimp
Suse