Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:0177

Опубликовано: 19 янв. 2022
Источник: rocky
Оценка: Important

Описание

Important: gegl04 security update

GEGL (Generic Graphics Library) is a graph-based image processing framework.

Security Fix(es):

  • gegl: shell expansion via a crafted pathname (CVE-2021-45463)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 4 лет назад

load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.

CVSS3: 7.8
redhat
около 4 лет назад

load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.

CVSS3: 7.8
nvd
около 4 лет назад

load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.

CVSS3: 7.8
debian
около 4 лет назад

load_cache in GEGL before 0.4.34 allows shell expansion when a pathnam ...

suse-cvrf
около 4 лет назад

Security update for gegl