Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GIMP 操作系统命令注入漏洞
Vulnerability Description
GIMP是GIMP团队的一款开源的位图图像编辑器。 GIMP 存在操作系统命令注入漏洞,该漏洞源于在构造的命令行中的路径名未转义或过滤时允许 shell 扩展。 这是由于使用系统库函数在magick-load 中执行ImageMagick 转换回退造成的。
CVSS Information
N/A
Vulnerability Type
N/A