Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-45463

Опубликовано: 23 дек. 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 7.8

Описание

load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

released

1:0.4.34-1
esm-apps/bionic

released

0.3.30-1ubuntu1+esm1
esm-apps/focal

released

0.4.22-3ubuntu0.1~esm1
esm-apps/jammy

released

1:0.4.34-1
esm-apps/noble

released

1:0.4.34-1
esm-apps/xenial

released

0.3.4-1ubuntu2+esm1
esm-infra-legacy/trusty

DNE

trusty/esm was released [0.2.0-4ubuntu1+esm1]
focal

ignored

end of standard support, was needed
hirsute

ignored

end of life

Показывать по

EPSS

Процентиль: 81%
0.01608
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
больше 3 лет назад

load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.

CVSS3: 7.8
nvd
больше 3 лет назад

load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.

CVSS3: 7.8
debian
больше 3 лет назад

load_cache in GEGL before 0.4.34 allows shell expansion when a pathnam ...

suse-cvrf
больше 3 лет назад

Security update for gegl

suse-cvrf
больше 3 лет назад

Security update for gegl

EPSS

Процентиль: 81%
0.01608
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3