Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-45463

Опубликовано: 15 дек. 2021
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.

Due to the use of the system command in the Magick-Load op used by gegl an attacker is able to craft a command line path that is able to lead to the execution of arbitrary shell commands that impacts availability, confidentiality and integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6geglOut of support scope
Red Hat Enterprise Linux 8geglAffected
Red Hat Enterprise Linux 8gimp:flatpak/geglAffected
Red Hat Enterprise Linux 9geglNot affected
Red Hat Enterprise Linux 7geglFixedRHSA-2022:016218.01.2022
Red Hat Enterprise Linux 8gegl04FixedRHSA-2022:017719.01.2022
Red Hat Enterprise Linux 8.2 Extended Update Supportgegl04FixedRHSA-2022:018419.01.2022
Red Hat Enterprise Linux 8.4 Extended Update Supportgegl04FixedRHSA-2022:017819.01.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2035383gegl: shell expansion via a crafted pathname

EPSS

Процентиль: 81%
0.01608
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 3 лет назад

load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.

CVSS3: 7.8
nvd
больше 3 лет назад

load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.

CVSS3: 7.8
debian
больше 3 лет назад

load_cache in GEGL before 0.4.34 allows shell expansion when a pathnam ...

suse-cvrf
больше 3 лет назад

Security update for gegl

suse-cvrf
больше 3 лет назад

Security update for gegl

EPSS

Процентиль: 81%
0.01608
Низкий

7.8 High

CVSS3