PT-2012-5273 · Gnu+1 · Gimp+1

Giles Coochey

·

Published

2012-08-31

·

Updated

2022-02-07

·

CVE-2012-4245

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GIMP version 2.6
Description The issue concerns the scriptfu network server in GIMP, which does not require authentication. This allows remote attackers to execute arbitrary commands via the python-fu-eval command.
Recommendations For GIMP version 2.6, consider disabling the scriptfu network server until a patch is available to prevent remote attackers from executing arbitrary commands.

Fix

RCE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-4245

Affected Products

Debian
Gimp