Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-2763

Опубликовано: 12 июл. 2012
Источник: debian
EPSS Высокий

Описание

Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gimpfixed2.8.0-1package

Примечания

  • Only exploitable in rare/theoretical setups

  • https://www.openwall.com/lists/oss-security/2012/05/31/1

  • http://www.reactionpenetrationtesting.co.uk/advisories/scriptfu-buffer-overflow-GIMP-2.6.html

  • http://www.reactionpenetrationtesting.co.uk/advisories/scriptfubof.c

EPSS

Процентиль: 100%
0.88834
Высокий

Связанные уязвимости

ubuntu
больше 13 лет назад

Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.

redhat
больше 13 лет назад

Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.

nvd
больше 13 лет назад

Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.

github
больше 3 лет назад

Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.

EPSS

Процентиль: 100%
0.88834
Высокий