CVE-2022-22816: Medium severity python imaging library (pillow) vulnerability
Published Jan 7, 2022
·Updated
pathgetbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.
Affected Software
6 affected componentsFixes available
debian/pillow
5.4.1-2+deb10u38.1.2+dfsg-0.3+deb11u19.4.0-1.110.1.0-1
pip/Pillow<9.0.0
9.0.0
Python Pillow<9.0.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Event History
Jan 7, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 12, 2022
Advisory Published
08:07 PM
Frequently Asked Questions
1
What is CVE-2022-22816?
CVE-2022-22816 is a vulnerability in the Pillow library, specifically in the path_getbbox function in path.c, which could result in a buffer over-read during the initialization of ImagePath.Path.
2
How does CVE-2022-22816 affect software?
CVE-2022-22816 affects the Pillow library versions before 9.0.0, as well as specific versions of the Debian Linux operating system.
3
What is the severity of CVE-2022-22816?
The severity of CVE-2022-22816 is medium, with a severity value of 6.5.
4
How can I fix CVE-2022-22816?
To fix CVE-2022-22816, update the Pillow library to version 9.0.0 or higher.
5
Where can I find more information about CVE-2022-22816?
You can find more information about CVE-2022-22816 on the NVD website and the official Pillow release notes for version 9.0.0.