Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-4245

Опубликовано: 16 авг. 2012
Источник: redhat
CVSS2: 5.1

Описание

The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command.

Отчет

Red Hat does not consider this to be a security flaw. The GIMP scriptfu server works as intended and should not be enabled in production environments as it was not designed to have any kind of security protection.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gimpWill not fix
Red Hat Enterprise Linux 6gimpWill not fix

Показывать по

Дополнительная информация

https://bugzilla.redhat.com/show_bug.cgi?id=855929gimp: arbitrary code execution without authentication in scriptfu network server

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command.

nvd
больше 13 лет назад

The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command.

debian
больше 13 лет назад

The scriptfu network server in GIMP 2.6 does not require authenticatio ...

github
больше 3 лет назад

The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command.

5.1 Medium

CVSS2