RHSA-2024:0754: Important: python-pillow security update
Important: python-pillow security update
Other sources
The python-pillow packages contain a Python image processing library that provides extensive file format support, an efficient internal representation, and powerful image-processing capabilities.Security Fix(es): pillow: Arbitrary Code Execution via the environment parameter (CVE-2023-50447) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 5.1.1-19.el8_8 - Upgrade
Upgrade
redhat/python-pillow-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-19.el8_8 - Upgrade
Upgrade
redhat/python-pillow-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.1-19.el8_8 - Upgrade
Upgrade
redhat/python3-pillowto a version that resolves this vulnerability.Fixed in 5.1.1-19.el8_8 - Upgrade
Upgrade
redhat/python3-pillow-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-19.el8_8 - Upgrade
Upgrade
redhat/python3-pillow-tk-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-19.el8_8 - Upgrade
Upgrade
redhat/python-pillow-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-19.el8_8.aa - Upgrade
Upgrade
redhat/python-pillow-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.1-19.el8_8.aa - Upgrade
Upgrade
redhat/python3-pillowto a version that resolves this vulnerability.Fixed in 5.1.1-19.el8_8.aa - Upgrade
Upgrade
redhat/python3-pillow-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-19.el8_8.aa - Upgrade
Upgrade
redhat/python3-pillow-tk-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-19.el8_8.aa - Upgrade
Upgrade
redhat/python3-pillow-develto a version that resolves this vulnerability.Fixed in 5.1.1-19.el8_8 - Upgrade
Upgrade
redhat/python3-pillow-docto a version that resolves this vulnerability.Fixed in 5.1.1-19.el8_8 - Upgrade
Upgrade
redhat/python3-pillow-tkto a version that resolves this vulnerability.Fixed in 5.1.1-19.el8_8 - Upgrade
Upgrade
redhat/python3-pillow-develto a version that resolves this vulnerability.Fixed in 5.1.1-19.el8_8.aa - Upgrade
Upgrade
redhat/python3-pillow-tkto a version that resolves this vulnerability.Fixed in 5.1.1-19.el8_8.aa - Configuration
Ensure the pillow code path that uses the image-processing API does not pass an attacker-controlled value into the environment parameter associated with CVE-2023-50447. Only allow trusted/validated input for that parameter.
python-pillow (pillow) environment parameter = Do not accept or pass untrusted input to the environment parameter that could trigger CVE-2023-50447
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0754?
The severity of RHSA-2024:0754 is classified as Important.
How do I fix RHSA-2024:0754?
To remediate RHSA-2024:0754, update the affected python-pillow packages to version 5.1.1-19.el8_8.
Which packages are affected by RHSA-2024:0754?
Affected packages include python-pillow, python3-pillow, and their related debuginfo and development packages.
Is RHSA-2024:0754 applicable to all Red Hat systems?
RHSA-2024:0754 applies to Red Hat Enterprise Linux versions that support the affected packages.
What should I do if I cannot update due to dependency issues?
If you encounter dependency issues while updating for RHSA-2024:0754, consider using the package manager's dependency resolution feature or consult your system administrator.