Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-2763
HistoryJul 12, 2012 - 12:00 a.m.

CVE-2012-2763

2012-07-1200:00:00
ubuntu.com
ubuntu.com
11

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.965

Percentile

99.6%

Buffer overflow in the readstr_upto function in
plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and
possibly 2.6.13, allows remote attackers to execute arbitrary code via a
long string in a command to the script-fu server.

Notes

Author Note
tyhicks The vast majority of gimp installs will not be using the script-fu network server
mdeslaur The script-fu network server should not be used in untrusted environments. We are not going to fix this, marking as ignored.

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.965

Percentile

99.6%