First published: Thu Jul 12 2012(Updated: )
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GIMP | <=2.6.13 |
http://git.gnome.org/browse/gimp/commit/?h=gimp-2-6&id=744f7a4a2b5acb8b531a6f5dd8744ebb95348fc2
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2763 has a high severity rating due to its potential to allow remote attackers to execute arbitrary code.
To fix CVE-2012-2763, users should upgrade GIMP to version 2.6.14 or later.
CVE-2012-2763 affects GIMP versions 2.6.12 and earlier, and possibly 2.6.13.
CVE-2012-2763 is a buffer overflow vulnerability found in the readstr_upto function.
Yes, CVE-2012-2763 can be exploited remotely through sending a long string command to the script-fu server.