CVE-2021-45463

load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
VendorProductVersion
geglgegl
𝑥
< 0.4.34
gimpgimp
𝑥
< 2.10.30
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gegl
bullseye
no-dsa
buster
no-dsa
stretch
no-dsa
bookworm
1:0.4.42-2
fixed
trixie
1:0.4.48-2.5
fixed
sid
1:0.4.50-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gegl
noble
Fixed 1:0.4.34-1
released
mantic
Fixed 1:0.4.34-1
released
lunar
Fixed 1:0.4.34-1
released
kinetic
Fixed 1:0.4.34-1
released
jammy
Fixed 1:0.4.34-1
released
impish
ignored
hirsute
ignored
focal
Fixed 0.4.22-3ubuntu0.1~esm1
released
bionic
Fixed 0.3.30-1ubuntu1+esm1
released
xenial
Fixed 0.3.4-1ubuntu2+esm1
released
trusty
Fixed 0.2.0-4ubuntu1+esm1
released