CVE-2012-4245
EPSS 1.1%
Description
The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command.
How to fix CVE-2012-4245
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/gimp—no fix listed
Is CVE-2012-4245 being exploited?
Low — EPSS is 1.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0