Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gimp | Sep 20, 2017 | Jul 12, 2012 |
| Debian | — | Upgrade gimp | Jul 30, 2024 | Jul 12, 2012 |
| Gentoo Linux | — | Upgrade media-gfx/gimp. | Oct 30, 2017 | Jul 12, 2012 |
| Oracle Solaris | — | Upgrade image/editor/gimp to version 2.6.10-0.175.0.11.0.3.0 on Solaris 11.0 | May 29, 2017 | Jul 12, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 30, 2012 |
| Suse | — | Upgrade libgimp-2_0-0-debuginfoUpgrade gimp-debugsourceUpgrade gimp-langUpgrade libgimpui-2_0-0-debuginfo-32bitUpgrade gimp-develUpgrade libgimp-2_0-0-debuginfo-32bitUpgrade gimp-help-browser-debuginfoUpgrade libgimpui-2_0-0-x86Upgrade libgimpui-2_0-0-32bitUpgrade gimp-help-browserUpgrade libgimpui-2_0-0-debuginfoUpgrade gimpUpgrade gimp-plugins-pythonUpgrade gimp-branding-upstreamUpgrade gimp-debuginfoUpgrade gimp-devel-debuginfoUpgrade gimp-plugins-python-debuginfoUpgrade libgimp-2_0-0-x86Upgrade libgimpui-2_0-0-debuginfo-x86Upgrade libgimp-2_0-0-32bitUpgrade libgimp-2_0-0Upgrade libgimpui-2_0-0Upgrade libgimp-2_0-0-debuginfo-x86 | Feb 17, 2015 | Jul 12, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub