CVE-2012-2763

GIMP <2.6.12-2.6.13 - RCE

Title source: llm

Description

Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/18973
exploitdb WORKING POC
by Joseph Sheridan · cdoswindows
https://www.exploit-db.com/exploits/18956
metasploit WORKING POC NORMAL
by Joseph Sheridan, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/gimp_script_fu.rb

Scores

EPSS 0.8883
EPSS Percentile 99.5%

Details

CWE
CWE-120
Status published
Products (1)
gimp/gimp < 2.6.13
Published Jul 12, 2012
Tracked Since Feb 18, 2026