Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-2763

Опубликовано: 30 мая 2012
Источник: redhat
CVSS2: 6.8
EPSS Высокий

Описание

Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.

Отчет

The Red Hat Security Response Team has rated this issue as having low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gimpNot affected
Red Hat Enterprise Linux 6gimpWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=824541gimp: Heap-based buffer overflow in the script-fu console by sending overly long arguments to script-fu server

EPSS

Процентиль: 100%
0.81722
Высокий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 14 лет назад

Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.

nvd
около 14 лет назад

Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.

debian
около 14 лет назад

Buffer overflow in the readstr_upto function in plug-ins/script-fu/tin ...

github
больше 4 лет назад

Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.

EPSS

Процентиль: 100%
0.81722
Высокий

6.8 Medium

CVSS2

Уязвимость CVE-2012-2763