CVE-2022-24303
published 2022-03-28CVE-2022-24303: Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
PriorityP348critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
2.81%
84.8th percentile
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pillow | < pillow 9.0.1-1 (bookworm) | pillow 9.0.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| paloalto | pan-os | — | — |
| python | pillow | < 9.0.1 | 9.0.1 |
| python | pillow | >= 0 < 8.1.2+dfsg-0.3+deb11u3 | 8.1.2+dfsg-0.3+deb11u3 |
| python | pillow | >= 0 < 9.0.1-1 | 9.0.1-1 |
| python | pillow | >= 0 < 9.0.1-1 | 9.0.1-1 |
| python | pillow | >= 0 < 9.0.1-1 | 9.0.1-1 |
| python | pillow | >= 0 < 9.0.1 | 9.0.1 |
| python | pillow | >= 0 < 7.0.0-4ubuntu0.7 | 7.0.0-4ubuntu0.7 |
| python | pillow | >= 0 < 9.0.1-1ubuntu0.1 | 9.0.1-1ubuntu0.1 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_ubuntu9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2022-12-14·CVSS 9.1
CVE-2022-24303 [CRITICAL] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
USN-5777-1 fixed vulnerabilities in Pillow (Python 3). This update provides the
corresponding updates for Pillow (Python 2) in Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that Pillow incorrectly handled the deletion of temporary
files when using a temporary directory that contains spaces. An attacker could
possibly use this issue to delete arbitrary files. This issue only affected
Ubuntu 20.04 LTS. (CVE-2022-24303)
It was discovered that Pillow incorrectly handled the decompression of highly
compressed GIF data. An attacker could possibly use this issue to cause Pillow
to crash, resulting in a denial of service. (CVE-2022-45198)
Instructions: In general, a standard system update wi
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2022-12-13·CVSS 9.1
CVE-2022-24303 [CRITICAL] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
It was discovered that Pillow incorrectly handled the deletion of temporary
files when using a temporary directory that contains spaces. An attacker could
possibly use this issue to delete arbitrary files. This issue only affected
Ubuntu 20.04 LTS. (CVE-2022-24303)
It was discovered that Pillow incorrectly handled the decompression of highly
compressed GIF data. An attacker could possibly use this issue to cause Pillow
to crash, resulting in a denial of service. (CVE-2022-45198)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-pillow: temporary directory with a space character allows removal of unrelated file after im.show() and related actions
vendor_redhat·2022-02-03·CVSS 9.1
CVE-2022-24303 [CRITICAL] CWE-1173 python-pillow: temporary directory with a space character allows removal of unrelated file after im.show() and related actions
python-pillow: temporary directory with a space character allows removal of unrelated file after im.show() and related actions
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
A flaw was found in python-pillow. The vulnerability occurs due to the not validated remove operation, leading to Improper input validation. This flaw allows an attacker to externally-influenced input commands that modify or remove the intended command.
Package: python-pillow (Red Hat Enterprise Linux 7) - Not affected
Package: python-pillow (Red Hat Enterprise Linux 8) - Not affected
Package: quay/quay-rhel8 (Red Hat Quay 3) - Affected
Debian
CVE-2022-24303: pillow - Pillow before 9.0.1 allows attackers to delete files because spaces in temporary...
vendor_debian·2022·CVSS 9.1
CVE-2022-24303 [CRITICAL] CVE-2022-24303: pillow - Pillow before 9.0.1 allows attackers to delete files because spaces in temporary...
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
Scope: local
bookworm: resolved (fixed in 9.0.1-1)
bullseye: resolved (fixed in 8.1.2+dfsg-0.3+deb11u3)
forky: resolved (fixed in 9.0.1-1)
sid: resolved (fixed in 9.0.1-1)
trixie: resolved (fixed in 9.0.1-1)
OSV
pillow-python2 vulnerabilities
osv·2022-12-14·CVSS 9.1
CVE-2022-24303 [CRITICAL] pillow-python2 vulnerabilities
pillow-python2 vulnerabilities
USN-5777-1 fixed vulnerabilities in Pillow (Python 3). This update provides the
corresponding updates for Pillow (Python 2) in Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that Pillow incorrectly handled the deletion of temporary
files when using a temporary directory that contains spaces. An attacker could
possibly use this issue to delete arbitrary files. This issue only affected
Ubuntu 20.04 LTS. (CVE-2022-24303)
It was discovered that Pillow incorrectly handled the decompression of highly
compressed GIF data. An attacker could possibly use this issue to cause Pillow
to crash, resulting in a denial of service. (CVE-2022-45198)
OSV
pillow vulnerabilities
osv·2022-12-13·CVSS 9.1
CVE-2022-24303 [CRITICAL] pillow vulnerabilities
pillow vulnerabilities
It was discovered that Pillow incorrectly handled the deletion of temporary
files when using a temporary directory that contains spaces. An attacker could
possibly use this issue to delete arbitrary files. This issue only affected
Ubuntu 20.04 LTS. (CVE-2022-24303)
It was discovered that Pillow incorrectly handled the decompression of highly
compressed GIF data. An attacker could possibly use this issue to cause Pillow
to crash, resulting in a denial of service. (CVE-2022-45198)
OSV
CVE-2022-24303: Pillow before 9
osv·2022-03-28·CVSS 9.1
CVE-2022-24303 [CRITICAL] CVE-2022-24303: Pillow before 9
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
GHSA
Path traversal in Pillow
ghsa·2022-03-11
CVE-2022-24303 [HIGH] CWE-22 Path traversal in Pillow
Path traversal in Pillow
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
OSV
Path traversal in Pillow
osv·2022-03-11
CVE-2022-24303 [HIGH] Path traversal in Pillow
Path traversal in Pillow
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/python-pillow/Pillow/pull/3450https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W4ZUXPKEX72O3E5IHBPVY5ZCPMJ4GHHV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XR6UP2XONXOVXI4446VY72R63YRO2YTP/https://pillow.readthedocs.io/en/stable/releasenotes/9.0.1.html#securityhttps://security.gentoo.org/glsa/202211-10https://github.com/python-pillow/Pillow/pull/3450https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W4ZUXPKEX72O3E5IHBPVY5ZCPMJ4GHHV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XR6UP2XONXOVXI4446VY72R63YRO2YTP/https://pillow.readthedocs.io/en/stable/releasenotes/9.0.1.html#securityhttps://security.gentoo.org/glsa/202211-10
2022-03-28
Published