CVE-2022-30595
published 2022-05-25CVE-2022-30595: libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.92%
77.6th percentile
libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pillow | < pillow 9.1.1-1 (bookworm) | pillow 9.1.1-1 (bookworm) |
| python | pillow | — | — |
| python | pillow | >= 0 < 9.1.1-1 | 9.1.1-1 |
| python | pillow | >= 0 < 9.1.1-1 | 9.1.1-1 |
| python | pillow | >= 0 < 9.1.1-1 | 9.1.1-1 |
| python | pillow | >= 9.1.0 < 9.1.1 | 9.1.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
python-pillow: heap buffer overflow in crafted TGA file
vendor_redhat·2022-05-17·CVSS 9.8
CVE-2022-30595 [CRITICAL] CWE-119 python-pillow: heap buffer overflow in crafted TGA file
python-pillow: heap buffer overflow in crafted TGA file
libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.
A heap buffer overflow vulnerability was found in python-pillow. This security vulnerability occurs when reading a TGA file with RLE packets that cross scan lines, where pillow reads the information past the end of the first line without deducting that from the length of the remaining file data.
Package: python-pillow (Red Hat Enterprise Linux 7) - Not affected
Package: python-pillow (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2022-30595: pillow - libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the proc...
vendor_debian·2022·CVSS 9.8
CVE-2022-30595 [CRITICAL] CVE-2022-30595: pillow - libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the proc...
libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.
Scope: local
bookworm: resolved (fixed in 9.1.1-1)
bullseye: resolved
forky: resolved (fixed in 9.1.1-1)
sid: resolved (fixed in 9.1.1-1)
trixie: resolved (fixed in 9.1.1-1)
OSV
Buffer over-flow in Pillow
osv·2022-05-26
CVE-2022-30595 [HIGH] Buffer over-flow in Pillow
Buffer over-flow in Pillow
When reading a TGA file with RLE packets that cross scan lines, Pillow reads the information past the end of the first line without deducting that from the length of the remaining file data. This vulnerability was introduced in Pillow 9.1.0, and can cause a heap buffer overflow.
Opening an image with a zero or negative height has been found to bypass a decompression bomb check. This will now raise a SyntaxError instead, in turn raising a PIL.UnidentifiedImageError.
GHSA
Buffer over-flow in Pillow
ghsa·2022-05-26
CVE-2022-30595 [HIGH] CWE-120 Buffer over-flow in Pillow
Buffer over-flow in Pillow
When reading a TGA file with RLE packets that cross scan lines, Pillow reads the information past the end of the first line without deducting that from the length of the remaining file data. This vulnerability was introduced in Pillow 9.1.0, and can cause a heap buffer overflow.
Opening an image with a zero or negative height has been found to bypass a decompression bomb check. This will now raise a SyntaxError instead, in turn raising a PIL.UnidentifiedImageError.
OSV
CVE-2022-30595: libImaging/TgaRleDecode
osv·2022-05-25·CVSS 9.8
CVE-2022-30595 [CRITICAL] CVE-2022-30595: libImaging/TgaRleDecode
libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-25
Published