First published: Fri Jan 07 2022(Updated: )
path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/Pillow | <9.0.0 | 9.0.0 |
Python Pillow | <9.0.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
debian/pillow | 5.4.1-2+deb10u3 8.1.2+dfsg-0.3+deb11u1 9.4.0-1.1 10.1.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22816 is a vulnerability in the Pillow library, specifically in the path_getbbox function in path.c, which could result in a buffer over-read during the initialization of ImagePath.Path.
CVE-2022-22816 affects the Pillow library versions before 9.0.0, as well as specific versions of the Debian Linux operating system.
The severity of CVE-2022-22816 is medium, with a severity value of 6.5.
To fix CVE-2022-22816, update the Pillow library to version 9.0.0 or higher.
You can find more information about CVE-2022-22816 on the NVD website and the official Pillow release notes for version 9.0.0.