Описание
path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.
A flaw was found in python-pillow. The vulnerability occurs due to improper initialization of image paths, leading to improperly initializing the ImagePath. This flaw allows an attacker to access unauthorized memory that causes memory access errors, incorrect results, or crashes.
Отчет
Red Hat Quay ships a vulnerable version of Pillow as a dependency of xhtml2pdf. The xhtml2pdf package is used in the invoice generation feature of Quay, however, the vulnerable ImagePath module is not used by xhtml2pdf. Therefore impact for Quay is rated Low.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | python-pillow | Out of support scope | ||
Red Hat Quay 3 | quay/quay-rhel8 | Affected | ||
Red Hat Enterprise Linux 8 | python-pillow | Fixed | RHSA-2022:0643 | 22.02.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.
path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.
path_getbbox in path.c in Pillow before 9.0.0 improperly initializes I ...
Уязвимость функции path_getbbox (path.c) библиотеки изображений Python Pillow, связанная с неверным ограничением пути к каталогу, позволяющая нарушителю получить доступ к произвольным файлам в системе
EPSS
6.5 Medium
CVSS3