Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2012-4245
HistoryAug 31, 2012 - 6:55 p.m.

CVE-2012-4245

2012-08-3118:55:05
Debian Security Bug Tracker
security-tracker.debian.org
16

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.012

Percentile

85.0%

The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command.

OSVersionArchitecturePackageVersionFilename
Debian12allgimp<= 2.10.34-1+deb12u2gimp_2.10.34-1+deb12u2_all.deb
Debian11allgimp<= 2.10.22-4+deb11u2gimp_2.10.22-4+deb11u2_all.deb
Debian999allgimp<= 2.10.38-2gimp_2.10.38-2_all.deb
Debian13allgimp<= 2.10.38-2gimp_2.10.38-2_all.deb

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.012

Percentile

85.0%