OS Command Injection in gegl - CVE-2021-45463
Published: December 28, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation, when a pathname in a constructed command line is not escaped or filtered. A remote unauthenticated attacker can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gimp
CentOS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
SUSE Linux Enterprise Module for Packagehub Subpackages
gegl-devel
libgegl-0_2-0-debuginfo
gegl-0_2-lang
gegl-0_2
gegl-0_2-debuginfo
gegl-debuginfo
gegl-debugsource
libgegl-0_2-0
gegl
gegl (Red Hat package)
typelib-1_0-Gegl-0_3
libgegl-0_3-0-debuginfo
libgegl-0_3-0
gegl-0_3-debuginfo
gegl-0_3
gegl04
gegl04 (Red Hat package)
libgegl-0_4-0
gegl-0_4
gegl-0_4-debuginfo
gegl-doc
gegl-0_4-lang
typelib-1_0-Gegl-0_4
libgegl-0_4-0-debuginfo
gimp
gimp-libs
gimp-devel
gimp-debuginfo
gimp-debugsource
gimp-help
How to mitigate CVE-2021-45463
Gimp - update to 2.10.30
gegl-devel - addressed in versions 0.2.0-15.6.1, 0.4.16-3.3.1
libgegl-0_2-0-debuginfo - update to 0.2.0-15.6.1
gegl-0_2-lang - update to 0.2.0-15.6.1
gegl-0_2 - update to 0.2.0-15.6.1
gegl-0_2-debuginfo - update to 0.2.0-15.6.1
gegl-debuginfo - addressed in versions 0.2.0-15.6.1, 0.4.16-3.3.1
gegl-debugsource - addressed in versions 0.2.0-15.6.1, 0.4.16-3.3.1
libgegl-0_2-0 - update to 0.2.0-15.6.1
gegl-devel - update to 0.2.0-19
gegl - update to 0.2.0-19
gegl (Red Hat package) - update to 0.2.0-19.el7_9.1
typelib-1_0-Gegl-0_3 - update to 0.3.34-3.3.1
libgegl-0_3-0-debuginfo - update to 0.3.34-3.3.1
libgegl-0_3-0 - update to 0.3.34-3.3.1
gegl-0_3-debuginfo - update to 0.3.34-3.3.1
gegl-0_3 - update to 0.3.34-3.3.1
gegl04 - update to 0.4.4-6
gegl04 (Red Hat package) - addressed in versions 0.4.4-6.el8_2.1, 0.4.4-6.el8_4.1, 0.4.4-6.el8_5.2
libgegl-0_4-0 - update to 0.4.16-3.3.1
gegl-0_4 - update to 0.4.16-3.3.1
gegl-0_4-debuginfo - update to 0.4.16-3.3.1
gegl-doc - update to 0.4.16-3.3.1
gegl - update to 0.4.16-3.3.1
gegl-0_4-lang - update to 0.4.16-3.3.1
typelib-1_0-Gegl-0_4 - update to 0.4.16-3.3.1
libgegl-0_4-0-debuginfo - update to 0.4.16-3.3.1
gegl04 - addressed in versions 0.4.34-1.fc34, 0.4.34-1.fc35
gimp - update to 2.10.6-10
gimp-libs - update to 2.10.6-10
gimp-devel - update to 2.10.6-10
gimp-debuginfo - update to 2.10.6-10
gimp-debugsource - update to 2.10.6-10
gimp-help - update to 2.10.6-10
External References
Related Security Bulletins
- OS command injection in Gnome GEGL
- GIMP update for Gnome GEGL
- CentOS 7 update for gegl
- Red Hat Enterprise Linux 7 update for gegl
- Red Hat Enterprise Linux 8 update for gegl04
- Red Hat Enterprise Linux 8.4 update for gegl04
- Red Hat Enterprise Linux 8.2 update for gegl04
- SUSE update for gegl
- SUSE update for gegl
- SUSE update for gegl
- openEuler update for gimp
- Fedora 35 update for gegl04
- Fedora 34 update for gegl04
- Anolis OS update for gegl
- Anolis OS update for gegl04