ALT-BU-2021-4760-1
Branch sisyphus_e2k update bulletin.
Package gimp updated to version 2.10.30-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2022-02388
Уязвимость функции load_cache графического редактора GIMP, позволяющая нарушителю передавать специальные данные приложению и выполнять произвольные команды ОС в целевой системе
Modified: 2024-11-21
CVE-2021-45463
load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.
- https://gitlab.gnome.org/GNOME/gegl/-/blob/master/docs/NEWS.adoc
- https://gitlab.gnome.org/GNOME/gegl/-/blob/master/docs/NEWS.adoc
- https://gitlab.gnome.org/GNOME/gegl/-/commit/bfce470f0f2f37968862129d5038b35429f2909b
- https://gitlab.gnome.org/GNOME/gegl/-/commit/bfce470f0f2f37968862129d5038b35429f2909b
- https://gitlab.gnome.org/GNOME/gegl/-/issues/298
- https://gitlab.gnome.org/GNOME/gegl/-/issues/298
- https://gitlab.gnome.org/GNOME/gimp/-/commit/e8a31ba4f2ce7e6bc34882dc27c97fba993f5868
- https://gitlab.gnome.org/GNOME/gimp/-/commit/e8a31ba4f2ce7e6bc34882dc27c97fba993f5868
- FEDORA-2022-a1c5b18362
- FEDORA-2022-a1c5b18362
- FEDORA-2022-5b5a738d7a
- FEDORA-2022-5b5a738d7a
- https://www.gimp.org/news/2021/12/21/gimp-2-10-30-released/
- https://www.gimp.org/news/2021/12/21/gimp-2-10-30-released/
Package libgegl updated to version 0.4.34-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2022-02388
Уязвимость функции load_cache графического редактора GIMP, позволяющая нарушителю передавать специальные данные приложению и выполнять произвольные команды ОС в целевой системе
Modified: 2024-11-21
CVE-2021-45463
load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.
- https://gitlab.gnome.org/GNOME/gegl/-/blob/master/docs/NEWS.adoc
- https://gitlab.gnome.org/GNOME/gegl/-/blob/master/docs/NEWS.adoc
- https://gitlab.gnome.org/GNOME/gegl/-/commit/bfce470f0f2f37968862129d5038b35429f2909b
- https://gitlab.gnome.org/GNOME/gegl/-/commit/bfce470f0f2f37968862129d5038b35429f2909b
- https://gitlab.gnome.org/GNOME/gegl/-/issues/298
- https://gitlab.gnome.org/GNOME/gegl/-/issues/298
- https://gitlab.gnome.org/GNOME/gimp/-/commit/e8a31ba4f2ce7e6bc34882dc27c97fba993f5868
- https://gitlab.gnome.org/GNOME/gimp/-/commit/e8a31ba4f2ce7e6bc34882dc27c97fba993f5868
- FEDORA-2022-a1c5b18362
- FEDORA-2022-a1c5b18362
- FEDORA-2022-5b5a738d7a
- FEDORA-2022-5b5a738d7a
- https://www.gimp.org/news/2021/12/21/gimp-2-10-30-released/
- https://www.gimp.org/news/2021/12/21/gimp-2-10-30-released/