CVE-2012-4245
Publication date 31 August 2012
Last updated 24 July 2024
Ubuntu priority
The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command.
Notes
References
Other references
- http://www.reactionpenetrationtesting.co.uk/GIMP-scriptfu-python-command-execution.html
- http://www.openwall.com/lists/oss-security/2012/08/20/1
- http://www.openwall.com/lists/oss-security/2012/08/17/2
- http://www.openwall.com/lists/oss-security/2012/08/16/6
- http://archives.neohapsis.com/archives/bugtraq/2012-08/0106.html
- https://www.cve.org/CVERecord?id=CVE-2012-4245