Lucene search

K
osvGoogleOSV:SUSE-SU-2024:1673-2
HistoryJun 13, 2024 - 9:22 a.m.

Security update for python-Pillow

2024-06-1309:22:50
Google
osv.dev
python-pillow
security update
vulnerabilities

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

Low

This update for python-Pillow fixes the following issues:

  • Fixed ImagePath.Path array handling (bsc#1194552, CVE-2022-22815, bsc#1194551, CVE-2022-22816)
  • Use snprintf instead of sprintf (bsc#1188574, CVE-2021-34552)
  • Fix Memory DOS in Icns, Ico and Blp Image Plugins. (bsc#1183110, CVE-2021-27921, bsc#1183108, CVE-2021-27922, bsc#1183107, CVE-2021-27923)
  • Fix OOB read in SgiRleDecode.c (bsc#1183102, CVE-2021-25293)
  • Use more specific regex chars to prevent ReDoS (bsc#1183101, CVE-2021-25292)
  • Fix negative size read in TiffDecode.c (bsc#1183105, CVE-2021-25290)
  • Raise ValueError if color specifier is too long (bsc#1190229, CVE-2021-23437)
  • Incorrect error code checking in TiffDecode.c (bsc#1183103, CVE-2021-25289)
  • OOB Write in TiffDecode.c (bsc#1180833, CVE-2020-35654)

References

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

Low