6.5
CVSSv3

CVE-2022-22816

Published: 10/01/2022 Updated: 31/01/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 571
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

path_getbbox in path.c in Pillow prior to 9.0.0 has a buffer over-read during initialization of ImagePath.Path.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

python pillow

debian debian linux 9.0

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

An incomplete fix was discovered in Pillow ...
Multiple security issues were discovered in Pillow, a Python imaging library, which could result in denial of service and potentially the execution of arbitrary code if malformed images are processed For the oldstable distribution (buster), these problems have been fixed in version 541-2+deb10u3 For the stable distribution (bullseye), these pro ...
Synopsis Important: python-pillow security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-pillow is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update ...
Synopsis Important: python-pillow security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-pillow is now available for Red Hat Enterprise Linux 84 Extended Update SupportRed Hat Product Secur ...
Synopsis Important: python-pillow security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-pillow is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update ...
Synopsis Important: python-pillow security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-pillow is now available for Red Hat Enterprise Linux 81 Update Services for SAP SolutionsRed Hat Pro ...
Synopsis Important: python-pillow security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-pillow is now available for Red Hat Enterprise Linux 82 Extended Update SupportRed Hat Product Secur ...
Synopsis Moderate: Migration Toolkit for Containers (MTC) 154 security update Type/Severity Security Advisory: Moderate Topic The Migration Toolkit for Containers (MTC) 154 is now availableRed Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System (CVSS) base score, whichg ...
A flaw was found in python-pillow The vulnerability occurs due to improper initialization of image paths, leading to a buffer over-read and improper initialization This flaw allows an attacker to unauthorized memory access that causes memory access errors, incorrect results, or crashes (CVE-2022-22815) A flaw was found in python-pillow The vuln ...
path_getbbox in pathc in Pillow before 900 has a buffer over-read during initialization of ImagePathPath ...
A flaw was found in python-pillow The vulnerability occurs due to improper initialization of image paths, leading to a buffer over-read and improper initialization This flaw allows an attacker to unauthorized memory access that causes memory access errors, incorrect results, or crashes (CVE-2022-22816) A flaw was found in python-pillow The vuln ...
A flaw was found in python-pillow The vulnerability occurs due to improper initialization of image paths, leading to a buffer over-read and improper initialization This flaw allows an attacker to unauthorized memory access that causes memory access errors, incorrect results, or crashes (CVE-2022-22816) A flaw was found in python-pillow The vuln ...