Hide Forgot
GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. Reference: https://gitlab.gnome.org/GNOME/gegl/-/blob/master/docs/NEWS.adoc Upstream patch: https://gitlab.gnome.org/GNOME/gegl/-/commit/bfce470f0f2f37968862129d5038b35429f2909b
Created gegl04 tracking bugs for this issue: Affects: fedora-all [bug 2035384]
Filed relevant trackers. However, at this time there is no gegl included in RHEL 9. Will keep an eye out for its possible inclusion in the future, but for right now, no effect on RHEL 9.
There is no gegl04 in RHEL9 as it is requirement for GIMP package, which is currently unavailable for RHEL-9, once GIMP release new version, gegl04 in version 0.4.34 or higher will become part of RHEL9 as well.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2022:0162 https://access.redhat.com/errata/RHSA-2022:0162
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:0177 https://access.redhat.com/errata/RHSA-2022:0177
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Extended Update Support Via RHSA-2022:0178 https://access.redhat.com/errata/RHSA-2022:0178
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Extended Update Support Via RHSA-2022:0184 https://access.redhat.com/errata/RHSA-2022:0184
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-45463