Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-22816

Опубликовано: 02 янв. 2022
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.

A flaw was found in python-pillow. The vulnerability occurs due to improper initialization of image paths, leading to a buffer over-read and improper initialization. This flaw allows an attacker to unauthorized memory access that causes memory access errors, incorrect results, or crashes.

Отчет

Red Hat Quay ships a vulnerable version of Pillow as a dependency of xhtml2pdf. The xhtml2pdf package is used in the invoice generation feature of Quay, however, the vulnerable ImagePath module is not used by xhtml2pdf. Therefore impact for Quay is rated Low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Quay 3quay/quay-rhel8Affected
Red Hat Enterprise Linux 7python-pillowFixedRHSA-2022:060922.02.2022
Red Hat Enterprise Linux 8python-pillowFixedRHSA-2022:064322.02.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutionspython-pillowFixedRHSA-2022:066924.02.2022
Red Hat Enterprise Linux 8.2 Extended Update Supportpython-pillowFixedRHSA-2022:066724.02.2022
Red Hat Enterprise Linux 8.4 Extended Update Supportpython-pillowFixedRHSA-2022:066524.02.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2042522python-pillow: buffer over-read during initialization of ImagePath.Path in path_getbbox() in path.c

EPSS

Процентиль: 36%
0.00149
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 3 лет назад

path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.

CVSS3: 6.5
nvd
больше 3 лет назад

path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.

CVSS3: 6.5
debian
больше 3 лет назад

path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read d ...

CVSS3: 6.5
github
больше 3 лет назад

Out-of-bounds Read in Pillow

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость функции path_getbbox (path.c) библиотеки изображений Python Pillow, связанная с чтением за границами буфера, позволяющая нарушителю получить доступ к конфиденциальной информации

EPSS

Процентиль: 36%
0.00149
Низкий

6.5 Medium

CVSS3