Description
GEGL before 0.4.34, as used (for example) in GIMP before 2.10.30, allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load.
Solution(s)
suse-upgrade-gegl-devel suse-upgrade-libgegl-0_2-0
ReferencesSUSE-SU-2021:4193-1 CVE-2021-45463