Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gimp | Sep 20, 2017 | Jul 12, 2012 |
| Debian | — | Upgrade gimp | Jul 30, 2024 | Jul 12, 2012 |
| Gentoo Linux | — | Upgrade media-gfx/gimp. | Oct 30, 2017 | Jul 12, 2012 |
| Oracle Solaris | — | Upgrade image/editor/gimp to version 2.6.10-0.175.0.11.0.3.0 on Solaris 11.0 | May 29, 2017 | Jul 12, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 30, 2012 |
| Suse | — | Upgrade gimp-debugsourceUpgrade libgimpui-2_0-0-x86Upgrade gimp-help-browserUpgrade libgimp-2_0-0-debuginfo-32bitUpgrade libgimpui-2_0-0-debuginfoUpgrade libgimp-2_0-0-debuginfoUpgrade gimp-langUpgrade libgimpui-2_0-0-debuginfo-32bitUpgrade libgimpui-2_0-0-32bitUpgrade gimp-develUpgrade gimp-help-browser-debuginfoUpgrade libgimpui-2_0-0-debuginfo-x86Upgrade gimp-plugins-python-debuginfoUpgrade gimp-devel-debuginfoUpgrade libgimp-2_0-0-32bitUpgrade gimp-branding-upstreamUpgrade libgimp-2_0-0-x86Upgrade gimp-debuginfoUpgrade gimpUpgrade libgimp-2_0-0-debuginfo-x86Upgrade libgimp-2_0-0Upgrade libgimpui-2_0-0Upgrade gimp-plugins-python | Feb 17, 2015 | Jul 12, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub