<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 10:51:56 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:0177 — Important: gegl04 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:0177</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: gegl04, AlmaLinux:8: gegl04-devel&lt;/p&gt;
&lt;p&gt;GEGL (Generic Graphics Library) is a graph-based image processing framework.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gegl: shell expansion via a crafted pathname (CVE-2021-45463)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: gegl04, AlmaLinux:8: gegl04-devel&lt;/p&gt;
&lt;p&gt;GEGL (Generic Graphics Library) is a graph-based image processing framework.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gegl: shell expansion via a crafted pathname (CVE-2021-45463)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:0177</guid>
    </item>
    <item>
      <title>bdu:2022-02388</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-02388</link>
      <description>bdu:2022-02388</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-02388</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-VE53254 — load_cache in GEGL before 0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-ve53254</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: gegl&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the gegl package. load_cache in GEGL before 0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: gegl&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the gegl package. load_cache in GEGL before 0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-ve53254</guid>
    </item>
    <item>
      <title>EUVD-2026-257442</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-257442</link>
      <description>EUVD-2026-257442</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-257442</guid>
    </item>
    <item>
      <title>fkie_cve-2021-45463</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-45463</link>
      <description>&lt;p&gt;load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-45463</guid>
    </item>
    <item>
      <title>GHSA-g9gv-9646-jvp8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g9gv-9646-jvp8</link>
      <description>&lt;p&gt;GEGL before 0.4.34, as used (for example) in GIMP before 2.10.30, allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GEGL before 0.4.34, as used (for example) in GIMP before 2.10.30, allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g9gv-9646-jvp8</guid>
    </item>
    <item>
      <title>gsd-2021-45463</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-45463</link>
      <description>gsd-2021-45463</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-45463</guid>
    </item>
    <item>
      <title>OESA-2022-1488 — gimp security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1488</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: gimp, openEuler:20.03-LTS-SP2: gimp, openEuler:20.03-LTS-SP3: gimp&lt;/p&gt;
&lt;p&gt;GIMP is a cross-platform image editor available for GNU/Linux, OS X, Windows and more operating systems. It is free software, you can change its source code and distribute your changes. Whether you are a graphic designer, photographer, illustrator, or scientist, GIMP provides you with sophisticated tools to get your job done. You can further enhance your productivity with GIMP thanks to many customization options and 3rd party plugins.&#13;
&#13;
Security Fix(es):&#13;
&#13;
GEGL before 0.4.34, as used (for example) in GIMP before 2.10.30, allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load.(CVE-2021-45463)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: gimp, openEuler:20.03-LTS-SP2: gimp, openEuler:20.03-LTS-SP3: gimp&lt;/p&gt;
&lt;p&gt;GIMP is a cross-platform image editor available for GNU/Linux, OS X, Windows and more operating systems. It is free software, you can change its source code and distribute your changes. Whether you are a graphic designer, photographer, illustrator, or scientist, GIMP provides you with sophisticated tools to get your job done. You can further enhance your productivity with GIMP thanks to many customization options and 3rd party plugins.&#13;
&#13;
Security Fix(es):&#13;
&#13;
GEGL before 0.4.34, as used (for example) in GIMP before 2.10.30, allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load.(CVE-2021-45463)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1488</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:4209-1 — Security update for gegl</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:4209-1</link>
      <description>&lt;p&gt;Security update for gegl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for gegl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:4209-1</guid>
    </item>
    <item>
      <title>RHSA-2022:0178 — Red Hat Security Advisory: gegl04 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:0178</link>
      <description>&lt;p&gt;gegl: shell expansion via a crafted pathname&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;gegl: shell expansion via a crafted pathname&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:0178</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:4193-1 — Security update for gegl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:4193-1</link>
      <description>&lt;p&gt;Security update for gegl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for gegl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:4193-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-45463</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-45463</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: gegl, Ubuntu:Pro:16.04:LTS: gegl, Ubuntu:Pro:18.04:LTS: gegl, Ubuntu:Pro:20.04:LTS: gegl, Ubuntu:22.04:LTS: gegl&lt;/p&gt;
&lt;p&gt;load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: gegl, Ubuntu:Pro:16.04:LTS: gegl, Ubuntu:Pro:18.04:LTS: gegl, Ubuntu:Pro:20.04:LTS: gegl, Ubuntu:22.04:LTS: gegl&lt;/p&gt;
&lt;p&gt;load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-45463</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2384 — Red Hat Enterprise Linux: Schwachstelle ermöglicht Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2384</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2384</guid>
    </item>
  </channel>
</rss>
