CVE-2021-22817
published 2022-02-09CVE-2021-22817: A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
9.9th percentile
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer Basic (All Versions prior to V1.2.1)
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| python | pillow | >= 0 < 5.1.0-1ubuntu0.8 | 5.1.0-1ubuntu0.8 |
| python | pillow | >= 0 < 7.0.0-4ubuntu0.6 | 7.0.0-4ubuntu0.6 |
| schneider-electric | vijeo_designer | < 1.2.1 | 1.2.1 |
| schneider-electric | vijeo_designer | < 6.2 | 6.2 |
| schneider-electric | vijeo_designer | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
pillow vulnerability
osv·2022-10-24·CVSS 7.5
CVE-2022-22817 pillow vulnerability
pillow vulnerability
USN-5227-1 fixed vulnerabilities in Pillow. It was discovered that the fix
for CVE-2022-22817 was incomplete. This update fixes the problem.
Original advisory details:
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to hang, resulting in a denial
of service. (CVE-2021-23437)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to crash, resulting in a denial
of service. This issue ony affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and
Ubuntu 21.04. (CVE-2021-34552)
It was discovered that Pill
GHSA
GHSA-qhqr-hrxf-m49q: A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local
ghsa_unreviewed·2022-02-11
CVE-2021-22817 [HIGH] CWE-276 GHSA-qhqr-hrxf-m49q: A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer Basic (All Versions prior to V1.2.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-09
Published