CVE-2022-45198
Summary
| CVE | CVE-2022-45198 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-14 07:15:00 UTC |
| Updated | 2023-01-10 20:11:00 UTC |
| Description | Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification). |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CWE - CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) (4.8) | MISC | cwe.mitre.org | |
| Pillow: Multiple Vulnerabilities (GLSA 202211-10) — Gentoo security | GENTOO | security.gentoo.org | |
| Release 9.2.0 · python-pillow/Pillow · GitHub | MISC | github.com | |
| Added GIF decompression bomb check by radarhere · Pull Request #6402 · python-pillow/Pillow · GitHub | MISC | github.com | |
| 855683 – <dev-python/pillow-9.2.0: vulnerable to gif extent(?) decompression bombs | MISC | bugs.gentoo.org | |
| Merge pull request #6403 from radarhere/gif_decompression_bomb · python-pillow/Pillow@11918ea · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182199 Debian Security Update for pillow (CVE-2022-45198)
- 199075 Ubuntu Security Notification for Pillow Vulnerabilities (USN-5777-1)
- 355121 Amazon Linux Security Advisory for python-pillow : ALAS2023-2023-146
- 672556 EulerOS Security Update for python-pillow (EulerOS-SA-2023-1134)
- 672563 EulerOS Security Update for python-pillow (EulerOS-SA-2023-1110)
- 672628 EulerOS Security Update for python-pillow (EulerOS-SA-2023-1397)
- 672641 EulerOS Security Update for python-pillow (EulerOS-SA-2023-1369)
- 672678 EulerOS Security Update for python-pillow (EulerOS-SA-2023-1415)
- 672690 EulerOS Security Update for python-pillow (EulerOS-SA-2023-1435)
- 672869 EulerOS Security Update for python-pillow (EulerOS-SA-2023-1606)
- 710682 Gentoo Linux Pillow Multiple Vulnerabilities (GLSA 202211-10)