CVE Vulnerabilities

CVE-2021-45463

Published: Dec 23, 2021 | Modified: Nov 07, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.

Affected Software

Name Vendor Start Version End Version
Gegl Gegl * 0.4.34 (excluding)
Red Hat Enterprise Linux 7 RedHat gegl-0:0.2.0-19.el7_9.1 *
Red Hat Enterprise Linux 8 RedHat gegl04-0:0.4.4-6.el8_5.2 *
Red Hat Enterprise Linux 8.2 Extended Update Support RedHat gegl04-0:0.4.4-6.el8_2.1 *
Red Hat Enterprise Linux 8.4 Extended Update Support RedHat gegl04-0:0.4.4-6.el8_4.1 *
Gegl Ubuntu bionic *
Gegl Ubuntu devel *
Gegl Ubuntu esm-apps/bionic *
Gegl Ubuntu esm-apps/focal *
Gegl Ubuntu esm-apps/xenial *
Gegl Ubuntu focal *
Gegl Ubuntu hirsute *
Gegl Ubuntu impish *
Gegl Ubuntu jammy *
Gegl Ubuntu kinetic *
Gegl Ubuntu lunar *
Gegl Ubuntu mantic *
Gegl Ubuntu noble *
Gegl Ubuntu oracular *
Gegl Ubuntu trusty *
Gegl Ubuntu trusty/esm *
Gegl Ubuntu upstream *
Gegl Ubuntu xenial *

References