CVE-2012-4245
Publication date 31 August 2012
Last updated 24 July 2024
Ubuntu priority
The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command.
Status
Package | Ubuntu Release | Status |
---|---|---|
gimp | 12.10 quantal |
Not affected
|
12.04 LTS precise | Ignored | |
11.10 oneiric | Ignored | |
11.04 natty | Ignored end of life | |
10.04 LTS lucid | Ignored | |
8.04 LTS hardy | Ignored end of life |
Notes
References
Other references
- http://www.reactionpenetrationtesting.co.uk/GIMP-scriptfu-python-command-execution.html
- http://www.openwall.com/lists/oss-security/2012/08/20/1
- http://www.openwall.com/lists/oss-security/2012/08/17/2
- http://www.openwall.com/lists/oss-security/2012/08/16/6
- http://archives.neohapsis.com/archives/bugtraq/2012-08/0106.html
- https://www.cve.org/CVERecord?id=CVE-2012-4245