Vulnerability record · CVE-2012-2763 · published 12 July 2012
CVE-2012-2763: GIMP Script-Fu server buffer overflow in readstr_upto
Gimp · Gimp
GIMP 2.6.12 and earlier (possibly 2.6.13) contains a classic buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c. A long string sent as a command to the Script-Fu server overflows the buffer, and the record notes this can lead to arbitrary code execution. The flaw matters because the Script-Fu server is a network-reachable component of a widely deployed image editor.
Description
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityNetwork-reachable, unauthenticated buffer overflow with public exploit material and a very high EPSS score, though it is not in KEV and affects an old GIMP release.
What it is
GIMP 2.6.12 and earlier (possibly 2.6.13) contains a classic buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c. A long string sent as a command to the Script-Fu server overflows the buffer, and the record notes this can lead to arbitrary code execution. The flaw matters because the Script-Fu server is a network-reachable component of a widely deployed image editor.
Impact
An attacker can execute arbitrary code in the context of the GIMP process, giving them the privileges of the user running GIMP. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.
Attack surface
Reached over the network via the Script-Fu server (AV:N, AC:L, Au:N), so no authentication and no user interaction are required per the vector. The description does not state whether the server must be explicitly enabled or bound to a reachable interface.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high at 0.817 (99.6th percentile). One reference is tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade GIMP to a version containing the fix commit 744f7a4a2b5acb8b531a6f5dd8744ebb95348fc2 or later; apply the vendor patch.
- Apply distribution updates from openSUSE and Gentoo advisories if you cannot upgrade GIMP directly.
- Disable or do not expose the Script-Fu server; bind it to localhost or block its port at the host firewall.
- Restrict network access to any host running GIMP with Script-Fu enabled.
- Treat GIMP as an untrusted-input application and avoid running it with elevated privileges.
Detection
- Monitor network traffic to the Script-Fu server port for unusually long command strings.
- Look for GIMP process crashes or abnormal termination consistent with a buffer overflow.
- Alert on unexpected child processes or outbound connections spawned by GIMP.
- Audit hosts for GIMP 2.6.12 or earlier and for exposed Script-Fu listeners.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-2763 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-2763), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.