CVE-2012-2763: Buffer Overflow
Published Jul 12, 2012
·Updated
Buffer overflow in the readstrupto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.
Affected Software
1 affected component
GIMP<=2.6.13
Remediation
Event History
Jul 12, 2012
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2763?
CVE-2012-2763 has a high severity rating due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2012-2763?
To fix CVE-2012-2763, users should upgrade GIMP to version 2.6.14 or later.
3
Which versions of GIMP are affected by CVE-2012-2763?
CVE-2012-2763 affects GIMP versions 2.6.12 and earlier, and possibly 2.6.13.
4
What type of vulnerability is CVE-2012-2763?
CVE-2012-2763 is a buffer overflow vulnerability found in the readstr_upto function.
5
Can CVE-2012-2763 be exploited remotely?
Yes, CVE-2012-2763 can be exploited remotely through sending a long string command to the script-fu server.