This script is Copyright (C) 2015 Tenable Network Security, Inc.
The remote Solaris system is missing a security patch for third-party
The remote Solaris system is missing necessary patches to address
security updates :
- Buffer overflow in the readstr_upto function in
plug-ins/script-fu/tinyscheme/ scheme.c in GIMP 2.6.12
and earlier, and possibly 2.6.13, allows remote
attackers to execute arbitrary code via a long string in
a command to the script-fu server. (CVE-2012-2763)
See also :
Upgrade to Solaris 11/11 SRU 11.4.
Risk factor :
High / CVSS Base Score : 7.5
Public Exploit Available : true