First published: Mon Nov 14 2022(Updated: )
Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Python Pillow | <9.3.0 | |
pip/pillow | >=9.2.0<9.3.0 | 9.3.0 |
<9.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-45199.
The severity of CVE-2022-45199 is high, with a severity value of 7.5.
Pillow before 9.3.0 allows denial of service by not properly handling a large value in the SAMPLESPERPIXEL tag, which can lead to a memory and runtime denial of service in TiffImagePlugin.py.
You can fix CVE-2022-45199 by updating your Pillow package to version 9.3.0 or later.
You can find more information about CVE-2022-45199 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-45199), [GitHub PR](https://github.com/python-pillow/Pillow/pull/6700), [GitHub Commit](https://github.com/python-pillow/Pillow/commit/2444cddab2f83f28687c7c20871574acbb6dbcf3).