REDHAT-BUG-2500057: High severity Pillow Pillow vulnerability
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pillowto a version that resolves this vulnerability.Fixed in 12.3.0
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2500057?
The severity of REDHAT-BUG-2500057 is high, rated at 7.
How do I fix REDHAT-BUG-2500057?
To fix REDHAT-BUG-2500057, upgrade Pillow to version 12.3.0 or later.
What kind of vulnerability is REDHAT-BUG-2500057?
REDHAT-BUG-2500057 is a vulnerability in the Pillow Python imaging library concerning uncompressed McIdas AREA image handling.
What are the potential impacts of REDHAT-BUG-2500057?
The potential impacts of REDHAT-BUG-2500057 include unauthorized memory access and possible exploitation through crafted image files.
Which software is affected by REDHAT-BUG-2500057?
The software affected by REDHAT-BUG-2500057 is the Pillow imaging library.