9.8
CVSSv3

CVE-2022-22817

Published: 10/01/2022 Updated: 22/03/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PIL.ImageMath.eval in Pillow prior to 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

python pillow

debian debian linux 9.0

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Debian Bug report logs - #1061172 pillow: CVE-2023-50447 Package: src:pillow; Maintainer for src:pillow is Matthias Klose <doko@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 20 Jan 2024 09:00:02 UTC Severity: grave Tags: security, upstream Found in version pillow/1010-1 Fixed in ver ...
An incomplete fix was discovered in Pillow ...
Multiple security issues were discovered in Pillow, a Python imaging library, which could result in denial of service and potentially the execution of arbitrary code if malformed images are processed For the oldstable distribution (buster), these problems have been fixed in version 541-2+deb10u3 For the stable distribution (bullseye), these pro ...
Synopsis Important: python-pillow security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-pillow is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update ...
Synopsis Important: python-pillow security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-pillow is now available for Red Hat Enterprise Linux 84 Extended Update SupportRed Hat Product Secur ...
Synopsis Important: python-pillow security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-pillow is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update ...
Synopsis Important: python-pillow security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-pillow is now available for Red Hat Enterprise Linux 81 Update Services for SAP SolutionsRed Hat Pro ...
Synopsis Important: python-pillow security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-pillow is now available for Red Hat Enterprise Linux 82 Extended Update SupportRed Hat Product Secur ...
Synopsis Moderate: Migration Toolkit for Containers (MTC) 154 security update Type/Severity Security Advisory: Moderate Topic The Migration Toolkit for Containers (MTC) 154 is now availableRed Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System (CVSS) base score, whichg ...
A flaw was found in python-pillow The vulnerability occurs due to improper initialization of image paths, leading to a buffer over-read and improper initialization This flaw allows an attacker to unauthorized memory access that causes memory access errors, incorrect results, or crashes (CVE-2022-22815) A flaw was found in python-pillow The vuln ...
PILImageMatheval in Pillow before 900 allows evaluation of arbitrary expressions, such as ones that use the Python exec method ...
A flaw was found in python-pillow The vulnerability occurs due to improper initialization of image paths, leading to a buffer over-read and improper initialization This flaw allows an attacker to unauthorized memory access that causes memory access errors, incorrect results, or crashes (CVE-2022-22816) A flaw was found in python-pillow The vuln ...
A flaw was found in python-pillow The vulnerability occurs due to improper initialization of image paths, leading to a buffer over-read and improper initialization This flaw allows an attacker to unauthorized memory access that causes memory access errors, incorrect results, or crashes (CVE-2022-22816) A flaw was found in python-pillow The vuln ...

Github Repositories

All CVE Exploits used by connor including code.

Exploits All CVE Exploits used by connor including code Current Exploits (Format: CVE | Codename | PrivEsc/RCE/Other) 2017: CVE-2017-0144 | EternalBlue | RCE 2021: CVE-2021-1675 | Print Nightmare | PrivEsc 2022: CVE-2022-22817 | None | Arbitary Code Execution CVE-2022-32221 | None | Buffer Overflow