UBUNTU-CVE-2023-50447
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-50447
UBUNTU-CVE-2023-50447
Summary:
Details: Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
References: https://ubuntu.com/security/CVE-2023-50447, https://duartecsantos.github.io/2023-01-02-CVE-2023-50447/, https://pillow.readthedocs.io/en/stable/releasenotes/10.2.0.html#imagemath-eval-restricted-environment-keys, https://devhub.checkmarx.com/cve-details/CVE-2023-50447/, http://www.openwall.com/lists/oss-security/2024/01/20/1, https://ubuntu.com/security/notices/USN-6618-1, https://www.cve.org/CVERecord?id=CVE-2023-50447, https://ubuntu.com/security/notices/USN-8135-1
Affected packages
Package
Name: pillow
Purl: pkg:deb/ubuntu/[email protected]+esm5?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
