REDHAT-BUG-2259479: High severity Python Pillow vulnerability
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
http://www.openwall.com/lists/oss-security/2024/01/20/1 https://devhub.checkmarx.com/cve-details/CVE-2023-50447/ https://duartecsantos.github.io/2023-01-02-CVE-2023-50447/ https://github.com/python-pillow/Pillow/releases
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2259479?
The severity of REDHAT-BUG-2259479 is classified as high due to the potential for arbitrary code execution.
How do I fix REDHAT-BUG-2259479?
To fix REDHAT-BUG-2259479, you should upgrade Pillow to version 10.1.1 or later.
What impact does REDHAT-BUG-2259479 have on applications?
REDHAT-BUG-2259479 allows an attacker to execute arbitrary code in applications using affected versions of Pillow.
Which versions of Pillow are affected by REDHAT-BUG-2259479?
Pillow versions up to and including 10.1.0 are affected by REDHAT-BUG-2259479.
Is REDHAT-BUG-2259479 related to any other vulnerabilities?
Yes, REDHAT-BUG-2259479 is different from CVE-2022-22817, which concerns the expression parameter.