CVE-2022-22815: Medium severity python imaging library (pillow) vulnerability
Published Jan 7, 2022
·Updated
pathgetbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.
Other sources
Pillow is the friendly PIL (Python Imaging Library) fork. pathgetbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.
Affected Software
6 affected componentsFixes available
debian/pillow
5.4.1-2+deb10u38.1.2+dfsg-0.3+deb11u19.4.0-1.110.1.0-1
pip/Pillow<9.0.0
9.0.0
Python Pillow<9.0.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Event History
Jan 7, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 12, 2022
Advisory Published
via GitHub·08:07 PM