Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gimp | Sep 20, 2017 | Jul 12, 2012 |
| Debian | — | Upgrade gimp | Jul 30, 2024 | Jul 12, 2012 |
| Gentoo Linux | — | Upgrade media-gfx/gimp. | Oct 30, 2017 | Jul 12, 2012 |
| Oracle Solaris | — | Upgrade image/editor/gimp to version 2.6.10-0.175.0.11.0.3.0 on Solaris 11.0 | May 29, 2017 | Jul 12, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 30, 2012 |
| Suse | — | Upgrade libgimp-2_0-0-32bitUpgrade libgimpui-2_0-0-debuginfo-x86Upgrade libgimp-2_0-0Upgrade libgimp-2_0-0-x86Upgrade gimp-branding-upstreamUpgrade gimp-devel-debuginfoUpgrade gimp-plugins-python-debuginfoUpgrade libgimpui-2_0-0Upgrade libgimp-2_0-0-debuginfo-x86Upgrade gimpUpgrade gimp-debuginfoUpgrade gimp-plugins-pythonUpgrade gimp-langUpgrade libgimpui-2_0-0-32bitUpgrade gimp-debugsourceUpgrade libgimp-2_0-0-debuginfoUpgrade libgimpui-2_0-0-debuginfo-32bitUpgrade libgimpui-2_0-0-x86Upgrade libgimp-2_0-0-debuginfo-32bitUpgrade gimp-help-browser-debuginfoUpgrade libgimpui-2_0-0-debuginfoUpgrade gimp-help-browserUpgrade gimp-devel | Feb 17, 2015 | Jul 12, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub