gimp: Heap-based buffer overflow in the script-fu console by sending overly long arguments to script-fu server
Published Jul 12, 2012
7.5
HIGHCVSS 2.0
EPSS 81.72%
Description
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
gimp
Not affected
Red Hat Enterprise Linux 6
gimp
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | gimp | Not affected | n/a |
| Red Hat Enterprise Linux 6 | gimp | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The Red Hat Security Response Team has rated this issue as having low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
References (14)
- http://git.gnome.org/browse/gimp/commit/?h=gimp-2-6&id=744f7a4a2b5acb8b531a6f5dd8744ebb95348fc2 x_refsource_CONFIRMExploitPatchVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00000.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2012-09/msg00043.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://secunia.com/advisories/50737 third-party-advisoryx_refsource_SECUNIABroken Link
- http://security.gentoo.org/glsa/glsa-201209-23.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://www.openwall.com/lists/oss-security/2012/05/31/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2012/07/01/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.reactionpenetrationtesting.co.uk/advisories/scriptfu-buffer-overflow-GIMP-2.6.html x_refsource_MISCThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2012-2763 Vendor Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=679215 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=824541 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2012-2743 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-2763
- https://www.cve.org/CVERecord?id=CVE-2012-2763
Change history (0)
No recorded changes yet.