← Vulnerability feed

Vulnerability record · CVE-2012-2763 · published 12 July 2012

CVE-2012-2763: GIMP Script-Fu server buffer overflow in readstr_upto

Gimp · Gimp

GIMP 2.6.12 and earlier (possibly 2.6.13) contains a classic buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c. A long string sent as a command to the Script-Fu server overflows the buffer, and the record notes this can lead to arbitrary code execution. The flaw matters because the Script-Fu server is a network-reachable component of a widely deployed image editor.

7.5 CVSS 2.0 High EPSS 82% · top 0.4% CWE-120 · Classic buffer overflow
7.5CVSS 2.0 base score
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityNetwork-reachable, unauthenticated buffer overflow with public exploit material and a very high EPSS score, though it is not in KEV and affects an old GIMP release.

What it is

GIMP 2.6.12 and earlier (possibly 2.6.13) contains a classic buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c. A long string sent as a command to the Script-Fu server overflows the buffer, and the record notes this can lead to arbitrary code execution. The flaw matters because the Script-Fu server is a network-reachable component of a widely deployed image editor.

Impact

An attacker can execute arbitrary code in the context of the GIMP process, giving them the privileges of the user running GIMP. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.

Attack surface

Reached over the network via the Script-Fu server (AV:N, AC:L, Au:N), so no authentication and no user interaction are required per the vector. The description does not state whether the server must be explicitly enabled or bound to a reachable interface.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high at 0.817 (99.6th percentile). One reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade GIMP to a version containing the fix commit 744f7a4a2b5acb8b531a6f5dd8744ebb95348fc2 or later; apply the vendor patch.
  • Apply distribution updates from openSUSE and Gentoo advisories if you cannot upgrade GIMP directly.
  • Disable or do not expose the Script-Fu server; bind it to localhost or block its port at the host firewall.
  • Restrict network access to any host running GIMP with Script-Fu enabled.
  • Treat GIMP as an untrusted-input application and avoid running it with elevated privileges.

Detection

  • Monitor network traffic to the Script-Fu server port for unusually long command strings.
  • Look for GIMP process crashes or abnormal termination consistent with a buffer overflow.
  • Alert on unexpected child processes or outbound connections spawned by GIMP.
  • Audit hosts for GIMP 2.6.12 or earlier and for exposed Script-Fu listeners.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://git.gnome.org/browse/gimp/commit/?h=gimp-2-6&id=744f7a4a2b5acb8b531a6f5dd8744ebb95348fc2 ExploitPatchVendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00000.html Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2012-09/msg00043.html Third Party Advisory
http://secunia.com/advisories/50737 Broken Link
http://security.gentoo.org/glsa/glsa-201209-23.xml Third Party Advisory
http://www.openwall.com/lists/oss-security/2012/05/31/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2012/07/01/1 Mailing ListThird Party Advisory
http://www.reactionpenetrationtesting.co.uk/advisories/scriptfu-buffer-overflow-GIMP-2.6.html Third Party Advisory
https://bugzilla.gnome.org/show_bug.cgi?id=679215 Issue TrackingThird Party Advisory
http://git.gnome.org/browse/gimp/commit/?h=gimp-2-6&id=744f7a4a2b5acb8b531a6f5dd8744ebb95348fc2 ExploitPatchVendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00000.html Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2012-09/msg00043.html Third Party Advisory
http://secunia.com/advisories/50737 Broken Link
http://security.gentoo.org/glsa/glsa-201209-23.xml Third Party Advisory
http://www.openwall.com/lists/oss-security/2012/05/31/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2012/07/01/1 Mailing ListThird Party Advisory
http://www.reactionpenetrationtesting.co.uk/advisories/scriptfu-buffer-overflow-GIMP-2.6.html Third Party Advisory
https://bugzilla.gnome.org/show_bug.cgi?id=679215 Issue TrackingThird Party Advisory

Track CVE-2012-2763 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-59090Gimp vulnerabilityA flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user …EPSS 0.61%9.3CVE-2010-4541Gimp out-of-bounds write vulnerabilityStack-based buffer overflow in the loadit function in plug-ins/common/sphere-designer.c in the SPHERE DESIGNER plugin in GIMP 2.6.11 allows user-assi…EPSS 6.8%9.3CVE-2009-3909Gimp integer overflow vulnerabilityInteger overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary co…EPSS 8.7%9.3CVE-2009-1570Gimp integer overflow vulnerabilityInteger overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a…EPSS 8.0%9.3CVE-2009-0723Gimp integer overflow vulnerabilityMultiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependen…EPSS 5.0%9.3CVE-2009-0733Gimp out-of-bounds write vulnerabilityMultiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta…EPSS 5.5%9.1CVE-2018-12713Gimp vulnerabilityGIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated b…EPSS 1.9%8.8CVE-2026-2044Gimp use of uninitialized resource vulnerabilityGIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …EPSS 0.99%

Source: NIST National Vulnerability Database (record CVE-2012-2763), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.