SB2012070323 - Buffer overflow in gimp (Alpine package)
Published: July 3, 2012
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2012-2763)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=b66f36cabcb08c2c0c87b798b8a4eb6ba822e01a
- https://git.alpinelinux.org/aports/commit/?id=7cbf993f1a9a0f30b833795efddd3979c2d646b9
- https://git.alpinelinux.org/aports/commit/?id=6f6c15d5702091599711d14bafecaec639c40df8
- https://git.alpinelinux.org/aports/commit/?id=222ced7f929deb2c0d2429b3d094cee12293e1fa