Vulnerability CVE-2022-24303: Information
Description
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
Severity: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
python3-module-Pillow | sisyphus | 9.0.1-alt1 | 10.3.0-alt1 | ALT-PU-2022-1236-1 | 295017 | Fixed |
python3-module-Pillow | sisyphus_e2k | 9.0.1-alt1 | 10.3.0-alt1 | ALT-PU-2022-4097-1 | - | Fixed |
python3-module-Pillow | sisyphus_riscv64 | 9.0.1-alt1 | 10.3.0-alt1 | ALT-PU-2022-4020-1 | - | Fixed |
python3-module-Pillow | p10 | 9.4.0-alt2 | 9.4.0-alt2 | ALT-PU-2023-7942-3 | 336131 | Fixed |
python3-module-Pillow | p10_e2k | 9.4.0-alt2 | 9.4.0-alt2 | ALT-PU-2023-8118-1 | - | Fixed |
python3-module-Pillow | c10f1 | 9.4.0-alt2 | 9.4.0-alt2 | ALT-PU-2023-8182-2 | 336766 | Fixed |
python3-module-Pillow | p11 | 9.0.1-alt1 | 10.3.0-alt1 | ALT-PU-2022-1236-1 | 295017 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://pillow.readthedocs.io/en/stable/releasenotes/9.0.1.html#security |
|
https://github.com/python-pillow/Pillow/pull/3450 |
|
GLSA-202211-10 |
|
FEDORA-2022-ee15b98ea1 | |
FEDORA-2022-64332f2a7c |