Bug 2042511 (CVE-2022-22815)
Summary: | CVE-2022-22815 python-pillow: improperly initializes ImagePath.Path in path_getbbox() in path.c | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | bdettelb, cstratak, epel-packagers-sig, infra-sig, manisandro, miminar, orion, python-maint, python-sig, torsava |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Pillow 9.0.0 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in python-pillow. The vulnerability occurs due to improper initialization of image paths, leading to improperly initializing the ImagePath. This flaw allows an attacker to access unauthorized memory that causes memory access errors, incorrect results, or crashes.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2022-05-06 03:15:19 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2042512, 2042513, 2042514, 2048363, 2048375 | ||
Bug Blocks: | 2042533 |
Description
Guilherme de Almeida Suckevicz
2022-01-19 16:17:16 UTC
Created mingw-python-pillow tracking bugs for this issue: Affects: fedora-all [bug 2042512] Created python-pillow tracking bugs for this issue: Affects: fedora-all [bug 2042513] Created python3-pillow tracking bugs for this issue: Affects: epel-7 [bug 2042514] This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-22815 |