CVE-2021-45463

Related Vulnerabilities: CVE-2021-45463  

Due to the use of the system command in the Magick-Load op used by gegl an attacker is able to craft a command line path that is able to lead to the execution of arbitrary shell commands that impacts availability, confidentiality and integrity.

Description

Due to the use of the system command in the Magick-Load op used by gegl an attacker is able to craft a command line path that is able to lead to the execution of arbitrary shell commands that impacts availability, confidentiality and integrity.

Additional Information

  • Bugzilla 2035383: CVE-2021-45463 gegl: shell expansion via a crafted pathname
  • CWE-20: Improper Input Validation
  • FAQ: Frequently asked questions about CVE-2021-45463