Vulnerability CVE-2022-22815: Information
Description
path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.
Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
python3-module-Pillow | sisyphus | 9.0.1-alt1 | 10.3.0-alt1 | ALT-PU-2022-1236-1 | 295017 | Fixed |
python3-module-Pillow | sisyphus_e2k | 9.0.1-alt1 | 10.3.0-alt1 | ALT-PU-2022-4097-1 | - | Fixed |
python3-module-Pillow | sisyphus_riscv64 | 9.0.1-alt1 | 10.3.0-alt1 | ALT-PU-2022-4020-1 | - | Fixed |
python3-module-Pillow | p10 | 9.4.0-alt2 | 9.4.0-alt2 | ALT-PU-2023-7942-3 | 336131 | Fixed |
python3-module-Pillow | p10_e2k | 9.4.0-alt2 | 9.4.0-alt2 | ALT-PU-2023-8118-1 | - | Fixed |
python3-module-Pillow | c10f1 | 9.4.0-alt2 | 9.4.0-alt2 | ALT-PU-2023-8182-2 | 336766 | Fixed |
python3-module-Pillow | p11 | 9.0.1-alt1 | 10.3.0-alt1 | ALT-PU-2022-1236-1 | 295017 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://github.com/python-pillow/Pillow/blob/c5d9223a8b5e9295d15b5a9b1ef1dae44c8499f3/src/path.c#L331 |
|
https://pillow.readthedocs.io/en/stable/releasenotes/9.0.0.html#fixed-imagepath-path-array-handling |
|
[debian-lts-announce] 20220123 [SECURITY] [DLA 2893-1] pillow security update |
|
DSA-5053 |
|
GLSA-202211-10 |
|