MGASA-2022-0166
Dashboard / Vulnerabilities / MGASA-2022-0166
MGASA-2022-0166
Summary: Updated python-pillow packages fix security vulnerability
Details: path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path. (CVE-2022-22815) path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path. (CVE-2022-22816) PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions (CVE-2022-22817) Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled. (CVE-2022-24303)
References: https://advisories.mageia.org/MGASA-2022-0166.html, https://bugs.mageia.org/show_bug.cgi?id=29887, https://ubuntu.com/security/notices/USN-5227-1, https://www.debian.org/security/2022/dsa-5053, https://lists.fedoraproject.org/archives/list/[email protected]/thread/CK3IGXU77EQTXZAYI2PTIAI4XLFS7AFP/, https://lists.fedoraproject.org/archives/list/[email protected]/thread/JR2LTB6KTUEU7YVPJ5MHA2GHOIL2JQQE/
Affected packages
Package
Name: python-pillow
Purl: pkg:rpm/mageia/python-pillow?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
