CVE-2022-22816

Description

path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
EPSS Score
Exploitation Probability
0.137

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2022-22815,CVE-2022-22816 are fixed in Python-pillow 9.0.0Windows
Python Imaging Library (USN-5227-1) python-pil_5.1.0-1ubuntu0.7_i386.debLinux
Python Imaging Library (USN-5227-1) python-pil_5.1.0-1ubuntu0.7_amd64.debLinux
Python Imaging Library (USN-5227-1) python3-pil_5.1.0-1ubuntu0.7_i386.debLinux
Python Imaging Library (USN-5227-1) python3-pil_5.1.0-1ubuntu0.7_amd64.debLinux
Python Imaging Library (USN-5227-1) python3-pil_7.0.0-4ubuntu0.5_amd64.debLinux
Python Imaging Library (USN-5227-1) python3-pil_8.1.2-1ubuntu0.2_amd64.debLinux
Python Imaging Library (USN-5227-1) python3-pil_8.1.2+dfsg-0.3ubuntu0.1_amd64.debLinux
(RHSA-2022:0609) python-pillow security update python-pillow-2.0.0-23.gitd1c6db8.el7_9.i686.rpmLinux
(RHSA-2022:0609) python-pillow security update python-pillow-2.0.0-23.gitd1c6db8.el7_9.x86_64.rpmLinux
(RHSA-2022:0609) python-pillow security update python-pillow-devel-2.0.0-23.gitd1c6db8.el7_9.i686.rpmLinux
(RHSA-2022:0609) python-pillow security update python-pillow-devel-2.0.0-23.gitd1c6db8.el7_9.x86_64.rpmLinux
(RHSA-2022:0609) python-pillow security update python-pillow-doc-2.0.0-23.gitd1c6db8.el7_9.x86_64.rpmLinux
(RHSA-2022:0609) python-pillow security update python-pillow-qt-2.0.0-23.gitd1c6db8.el7_9.x86_64.rpmLinux
(RHSA-2022:0609) python-pillow security update python-pillow-sane-2.0.0-23.gitd1c6db8.el7_9.x86_64.rpmLinux
(RHSA-2022:0609) python-pillow security update python-pillow-tk-2.0.0-23.gitd1c6db8.el7_9.x86_64.rpmLinux
(RHSA-2022:0643) python-pillow security update python-pillow-debugsource-5.1.1-18.el8_5.x86_64.rpmLinux
(RHSA-2022:0643) python-pillow security update python3-pillow-5.1.1-18.el8_5.x86_64.rpmLinux
Python3-pillow update (ELSA-2022-0643) python3-pillow-5.1.1-18.el8_5.i686.rpmLinux
Python3-pillow update (ELSA-2022-0643) python3-pillow-5.1.1-18.el8_5.x86_64.rpmLinux
Python3-pillow-devel update (ELSA-2022-0643) python3-pillow-devel-5.1.1-18.el8_5.i686.rpmLinux
Python3-pillow-devel update (ELSA-2022-0643) python3-pillow-devel-5.1.1-18.el8_5.x86_64.rpmLinux
Python3-pillow-doc update (ELSA-2022-0643) python3-pillow-doc-5.1.1-18.el8_5.noarch.rpmLinux
Python3-pillow-tk update (ELSA-2022-0643) python3-pillow-tk-5.1.1-18.el8_5.x86_64.rpmLinux
python-pillow security update (RLSA-2022:0643) python3-pillow-5.1.1-18.el8_5.x86_64.rpmLinux
python38 update (TU-CESAS-0024) python38-pip-19.3.1-7.module_el8+640+ebf3d03c.noarch.rpmLinux
python38 update (TU-CESAS-0024) python38-idle-3.8.17-2.module_el8+640+ebf3d03c.x86_64.rpmLinux
python3 update (TU-CESAS-0024) python3-pillow-5.1.1-19.el8.x86_64.rpmLinux
python38 update (TU-CESAS-0024) python38-tkinter-3.8.17-2.module_el8+640+ebf3d03c.x86_64.rpmLinux
python3.11 update (TU-CESAS-0024) python3.11-urllib3-1.26.12-2.el8.noarch.rpmLinux
python38 update (TU-CESAS-0024) python38-pip-wheel-19.3.1-7.module_el8+640+ebf3d03c.noarch.rpmLinux
(RHSA-2022:0643)Important: security update python-pillow-debuginfo-5.1.1-18.el8_5.x86_64.rpmLinux
(RHSA-2022:0643)Important: security update python3-pillow-debuginfo-5.1.1-18.el8_5.x86_64.rpmLinux
(RHSA-2022:0643)Important: security update python3-pillow-tk-debuginfo-5.1.1-18.el8_5.x86_64.rpmLinux
python-pillow Security Update (ALAS2023-2023-057) python3-pillow-9.0.1-6.amzn2023.0.3.x86_64.rpmLinux
python-pillow Security Update (ALAS2023-2023-057) python3-pillow-devel-9.0.1-6.amzn2023.0.3.x86_64.rpmLinux
python-pillow Security Update (ALAS2023-2023-057) python3-pillow-tk-9.0.1-6.amzn2023.0.3.x86_64.rpmLinux
Vulnerabilities CVE-2022-22815,CVE-2022-22816 are fixed in Python-pillow for linux 9.0.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234