CVE-2012-2763

Description

Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
88.834

Associated Vulnerability

VulnerabilityOS Platform
Upgrade gimp 2.6.7 to latest versionWindows
Multiple Vulnerabilities are affected in GIMP 2.6.7Windows
Multiple Vulnerabilities are affected in GIMP 2.6.11Windows
Vulnerabilities CVE-2012-2763,CVE-2012-3402,CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.2Windows
Vulnerabilities CVE-2012-2763,CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.1Windows
Vulnerabilities CVE-2012-2763,CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.2Windows
Multiple Vulnerabilities are affected in GIMP 2.6.1Windows
Vulnerabilities CVE-2012-2763,CVE-2012-3403,CVE-2012-3481,CVE-2012-4245 are affected in GIMP 2.6.12Windows
Vulnerabilities CVE-2012-2763,CVE-2012-3403,CVE-2012-3481,CVE-2012-4245 are affected in GIMP 2.6.13Windows
Multiple Vulnerabilities are affected in GIMP 2.6.6Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234