CVE-2021-45463

load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
Affected Products (NVD)
VendorProductVersion
geglgegl
𝑥
< 0.4.34
gimpgimp
𝑥
< 2.10.30
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gegl
bookworm
1:0.4.42-2
fixed
bullseye
no-dsa
buster
no-dsa
sid
1:0.4.50-1
fixed
stretch
no-dsa
trixie
1:0.4.48-2.5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gegl
bionic
Fixed 0.3.30-1ubuntu1+esm1
released
focal
Fixed 0.4.22-3ubuntu0.1~esm1
released
hirsute
ignored
impish
ignored
jammy
Fixed 1:0.4.34-1
released
kinetic
Fixed 1:0.4.34-1
released
lunar
Fixed 1:0.4.34-1
released
mantic
Fixed 1:0.4.34-1
released
noble
Fixed 1:0.4.34-1
released
trusty
Fixed 0.2.0-4ubuntu1+esm1
released
xenial
Fixed 0.3.4-1ubuntu2+esm1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
gegl-0_3
suse enterprise desktop 15 SP2
0.3.34-3.3.1
fixed
suse enterprise desktop 15 SP3
0.3.34-3.3.1
fixed
suse enterprise desktop 15 SP4
0.3.34-3.3.1
fixed
suse enterprise desktop 15 SP5
0.3.34-3.3.1
fixed
suse enterprise desktop 15 SP6
0.3.34-3.3.1
fixed
suse enterprise desktop 15 SP7
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP2
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP3
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP4
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP5
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP6
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP7
0.3.34-3.3.1
fixed
suse enterprise server 15 SP2
0.3.34-3.3.1
fixed
suse enterprise server 15 SP3
0.3.34-3.3.1
fixed
suse enterprise server 15 SP4
0.3.34-3.3.1
fixed
suse enterprise server 15 SP5
0.3.34-3.3.1
fixed
suse enterprise server 15 SP6
0.3.34-3.3.1
fixed
suse enterprise server 15 SP7
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP2
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP3
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP4
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP5
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP6
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP7
0.3.34-3.3.1
fixed
gegl-0_4
suse enterprise desktop 15 SP2
0.4.16-3.3.1
fixed
suse enterprise desktop 15 SP3
0.4.16-3.3.1
fixed
suse enterprise sap 15 SP2
0.4.16-3.3.1
fixed
suse enterprise sap 15 SP3
0.4.16-3.3.1
fixed
suse enterprise server 15 SP2
0.4.16-3.3.1
fixed
suse enterprise server 15 SP3
0.4.16-3.3.1
fixed
suse enterprise workstation 15 SP2
0.4.16-3.3.1
fixed
suse enterprise workstation 15 SP3
0.4.16-3.3.1
fixed
gegl-0_4-lang
suse enterprise desktop 15 SP2
0.4.16-3.3.1
fixed
suse enterprise desktop 15 SP3
0.4.16-3.3.1
fixed
suse enterprise sap 15 SP2
0.4.16-3.3.1
fixed
suse enterprise sap 15 SP3
0.4.16-3.3.1
fixed
suse enterprise server 15 SP2
0.4.16-3.3.1
fixed
suse enterprise server 15 SP3
0.4.16-3.3.1
fixed
suse enterprise workstation 15 SP2
0.4.16-3.3.1
fixed
suse enterprise workstation 15 SP3
0.4.16-3.3.1
fixed
gegl-devel
suse enterprise desktop 15 SP2
0.4.16-3.3.1
fixed
suse enterprise desktop 15 SP3
0.4.16-3.3.1
fixed
suse enterprise sap 15 SP2
0.4.16-3.3.1
fixed
suse enterprise sap 15 SP3
0.4.16-3.3.1
fixed
suse enterprise server 15 SP2
0.4.16-3.3.1
fixed
suse enterprise server 15 SP3
0.4.16-3.3.1
fixed
suse enterprise workstation 15 SP2
0.4.16-3.3.1
fixed
suse enterprise workstation 15 SP3
0.4.16-3.3.1
fixed
libgegl-0_3-0
suse enterprise desktop 15 SP2
0.3.34-3.3.1
fixed
suse enterprise desktop 15 SP3
0.3.34-3.3.1
fixed
suse enterprise desktop 15 SP4
0.3.34-3.3.1
fixed
suse enterprise desktop 15 SP5
0.3.34-3.3.1
fixed
suse enterprise desktop 15 SP6
0.3.34-3.3.1
fixed
suse enterprise desktop 15 SP7
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP2
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP3
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP4
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP5
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP6
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP7
0.3.34-3.3.1
fixed
suse enterprise server 15 SP2
0.3.34-3.3.1
fixed
suse enterprise server 15 SP3
0.3.34-3.3.1
fixed
suse enterprise server 15 SP4
0.3.34-3.3.1
fixed
suse enterprise server 15 SP5
0.3.34-3.3.1
fixed
suse enterprise server 15 SP6
0.3.34-3.3.1
fixed
suse enterprise server 15 SP7
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP2
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP3
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP4
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP5
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP6
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP7
0.3.34-3.3.1
fixed
libgegl-0_4-0
suse enterprise desktop 15 SP2
0.4.16-3.3.1
fixed
suse enterprise desktop 15 SP3
0.4.16-3.3.1
fixed
suse enterprise sap 15 SP2
0.4.16-3.3.1
fixed
suse enterprise sap 15 SP3
0.4.16-3.3.1
fixed
suse enterprise server 15 SP2
0.4.16-3.3.1
fixed
suse enterprise server 15 SP3
0.4.16-3.3.1
fixed
suse enterprise workstation 15 SP2
0.4.16-3.3.1
fixed
suse enterprise workstation 15 SP3
0.4.16-3.3.1
fixed
typelib-1_0-Gegl-0_3
suse enterprise desktop 15 SP2
0.3.34-3.3.1
fixed
suse enterprise desktop 15 SP3
0.3.34-3.3.1
fixed
suse enterprise desktop 15 SP4
0.3.34-3.3.1
fixed
suse enterprise desktop 15 SP5
0.3.34-3.3.1
fixed
suse enterprise desktop 15 SP6
0.3.34-3.3.1
fixed
suse enterprise desktop 15 SP7
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP2
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP3
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP4
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP5
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP6
0.3.34-3.3.1
fixed
suse enterprise sap 15 SP7
0.3.34-3.3.1
fixed
suse enterprise server 15 SP2
0.3.34-3.3.1
fixed
suse enterprise server 15 SP3
0.3.34-3.3.1
fixed
suse enterprise server 15 SP4
0.3.34-3.3.1
fixed
suse enterprise server 15 SP5
0.3.34-3.3.1
fixed
suse enterprise server 15 SP6
0.3.34-3.3.1
fixed
suse enterprise server 15 SP7
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP2
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP3
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP4
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP5
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP6
0.3.34-3.3.1
fixed
suse enterprise workstation 15 SP7
0.3.34-3.3.1
fixed
typelib-1_0-Gegl-0_4
suse enterprise desktop 15 SP2
0.4.16-3.3.1
fixed
suse enterprise desktop 15 SP3
0.4.16-3.3.1
fixed
suse enterprise sap 15 SP2
0.4.16-3.3.1
fixed
suse enterprise sap 15 SP3
0.4.16-3.3.1
fixed
suse enterprise server 15 SP2
0.4.16-3.3.1
fixed
suse enterprise server 15 SP3
0.4.16-3.3.1
fixed
suse enterprise workstation 15 SP2
0.4.16-3.3.1
fixed
suse enterprise workstation 15 SP3
0.4.16-3.3.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
gegl
RHEL 7
0:0.2.0-19.el7_9.1
fixed
gegl-devel
RHEL 7
0:0.2.0-19.el7_9.1
fixed
gegl04
RHEL 8
0:0.4.4-6.el8_5.2
fixed
RHEL 8.2 AUS
0:0.4.4-6.el8_2.1
fixed
RHEL 8.2 E4S
0:0.4.4-6.el8_2.1
fixed
RHEL 8.2 EUS
0:0.4.4-6.el8_2.1
fixed
RHEL 8.2 TUS
0:0.4.4-6.el8_2.1
fixed
RHEL 8.4 AUS
0:0.4.4-6.el8_4.1
fixed
RHEL 8.4 E4S
0:0.4.4-6.el8_4.1
fixed
RHEL 8.4 EUS
0:0.4.4-6.el8_4.1
fixed
RHEL 8.4 TUS
0:0.4.4-6.el8_4.1
fixed
gegl04-devel
RHEL 8
0:0.4.4-6.el8_5.2
fixed
RHEL 8.2 AUS
0:0.4.4-6.el8_2.1
fixed
RHEL 8.2 E4S
0:0.4.4-6.el8_2.1
fixed
RHEL 8.2 EUS
0:0.4.4-6.el8_2.1
fixed
RHEL 8.2 TUS
0:0.4.4-6.el8_2.1
fixed
RHEL 8.4 AUS
0:0.4.4-6.el8_4.1
fixed
RHEL 8.4 E4S
0:0.4.4-6.el8_4.1
fixed
RHEL 8.4 EUS
0:0.4.4-6.el8_4.1
fixed
RHEL 8.4 TUS
0:0.4.4-6.el8_4.1
fixed