Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gimp | Sep 20, 2017 | Jul 12, 2012 |
| Debian | — | Upgrade gimp | Jul 30, 2024 | Jul 12, 2012 |
| Gentoo Linux | — | Upgrade media-gfx/gimp. | Oct 30, 2017 | Jul 12, 2012 |
| Oracle Solaris | — | Upgrade image/editor/gimp to version 2.6.10-0.175.0.11.0.3.0 on Solaris 11.0 | May 29, 2017 | Jul 12, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 30, 2012 |
| Suse | — | Upgrade gimp-langUpgrade libgimpui-2_0-0-debuginfo-32bitUpgrade libgimpui-2_0-0-x86Upgrade libgimpui-2_0-0-32bitUpgrade libgimp-2_0-0-debuginfoUpgrade gimp-debugsourceUpgrade gimp-help-browserUpgrade gimp-develUpgrade libgimpui-2_0-0-debuginfoUpgrade libgimp-2_0-0-debuginfo-32bitUpgrade gimp-help-browser-debuginfoUpgrade libgimp-2_0-0-32bitUpgrade libgimp-2_0-0-debuginfo-x86Upgrade gimpUpgrade libgimpui-2_0-0Upgrade gimp-branding-upstreamUpgrade libgimp-2_0-0-x86Upgrade gimp-devel-debuginfoUpgrade libgimp-2_0-0Upgrade gimp-plugins-pythonUpgrade gimp-plugins-python-debuginfoUpgrade libgimpui-2_0-0-debuginfo-x86Upgrade gimp-debuginfo | Feb 17, 2015 | Jul 12, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub