CVE-2023-50447
Summary
| CVE | CVE-2023-50447 |
| State | PUBLISHED |
| Assigner | Unknown |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-01-19 20:15:00 UTC |
| Updated | 2024-03-27 21:15:00 UTC |
| Description | Description unavailable. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| oss-security - Pillow 10.2.0 released, fixes CVE-2023-50447 |
|
www.openwall.com |
Mailing List, Third Party Advisory |
| Arbitrary Code Execution in Pillow |
|
duartecsantos.github.io |
Exploit, Third Party Advisory |
| Releases · python-pillow/Pillow · GitHub |
|
github.com |
Release Notes |
| [SECURITY] [DLA 3724-1] pillow security update |
|
lists.debian.org |
|
| duartecsantos.github.io/2024-01-02-CVE-2023-50447 |
|
duartecsantos.github.io |
|
| Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') - CVE-2023-50447 - DevHub |
|
devhub.checkmarx.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161363 Oracle Enterprise Linux Security Update for python-pillow (ELSA-2024-0857)
- 161365 Oracle Enterprise Linux Security Update for python-pillow (ELSA-2024-0893)
- 200085 Ubuntu Security Notification for Pillow Vulnerabilities (USN-6618-1)
- 242920 Red Hat Update for python-pillow (RHSA-2024:0754)
- 242933 Red Hat Update for python-pillow (RHSA-2024:0857)
- 242980 Red Hat Update for python-pillow (RHSA-2024:0893)
- 242992 Red Hat Update for python-pillow (RHSA-2024:1060)
- 242995 Red Hat Update for python-pillow (RHSA-2024:1058)
- 257308 CentOS Security Update for python-pillow (CESA-2024:0857)
- 296109 Oracle Solaris 11.4 Support Repository Update (SRU) 67.164.1 Missing (CPUJAN2024)
- 357074 Amazon Linux Security Advisory for python-pillow : ALAS2-2024-2444
- 357119 Amazon Linux Security Advisory for python-pillow : ALAS2023-2024-512
- 379436 Alibaba Cloud Linux Security Update for python-pillow (ALINUX2-SA-2024:0010)
- 510699 Alpine Linux Security Update for py3-pillow
- 6000454 Debian Security Update for pillow (DLA 3724-1)
- 673374 EulerOS Security Update for python-pillow (EulerOS-SA-2024-1247)
- 673666 EulerOS Security Update for python-pillow (EulerOS-SA-2024-1225)
- 674144 EulerOS Security Update for python-pillow (EulerOS-SA-2024-1516)
- 674146 EulerOS Security Update for python-pillow (EulerOS-SA-2024-1495)
- 755642 SUSE Enterprise Linux Security Update for python-Pillow (SUSE-SU-2024:0185-1)
- 755649 SUSE Enterprise Linux Security Update for python-Pillow (SUSE-SU-2024:0205-1)
- 941586 AlmaLinux Security Update for python-pillow (ALSA-2024:0893)
- 996819 Python (Pip) Security Update for Pillow (GHSA-3f63-hfp8-52jq)