CVE-2012-2763
GIMP <2.6.12-2.6.13 - RCE
Title source: llmDescription
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/18973
metasploit
WORKING POC
NORMAL
by Joseph Sheridan, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/gimp_script_fu.rb
References (9)
Scores
EPSS
0.8883
EPSS Percentile
99.5%
Details
CWE
CWE-120
Status
published
Products (1)
gimp/gimp
< 2.6.13
Published
Jul 12, 2012
Tracked Since
Feb 18, 2026