OESA-2024-1098
Dashboard / Vulnerabilities / OESA-2024-1098
Summary: python-pillow security update
Details: Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging \ Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift. %package -n python3-pillow Summary: Python 3 image processing library Provides: python3-imaging = - Security Fix(es): Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).(CVE-2023-50447)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1098, https://nvd.nist.gov/vuln/detail/CVE-2023-50447
Affected packages
Package
Name: python-pillow
Purl: pkg:rpm/openEuler/python-pillow&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
