CVE-2022-45198
published 2022-11-14CVE-2022-45198: Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.18%
64.3th percentile
Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pillow | < pillow 9.2.0-1 (bookworm) | pillow 9.2.0-1 (bookworm) |
| paloalto | pan-os | — | — |
| python | pillow | < 9.2.0 | 9.2.0 |
| python | pillow | >= 0 < 8.1.2+dfsg-0.3+deb11u3 | 8.1.2+dfsg-0.3+deb11u3 |
| python | pillow | >= 0 < 9.2.0-1 | 9.2.0-1 |
| python | pillow | >= 0 < 9.2.0-1 | 9.2.0-1 |
| python | pillow | >= 0 < 9.2.0-1 | 9.2.0-1 |
| python | pillow | >= 0 < 9.2.0 | 9.2.0 |
| python | pillow | >= 0 < 7.0.0-4ubuntu0.7 | 7.0.0-4ubuntu0.7 |
| python | pillow | >= 0 < 9.0.1-1ubuntu0.1 | 9.0.1-1ubuntu0.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv9.1CRITICAL
vendor_ubuntu9.1CRITICAL
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
pillow-python2 vulnerabilities
osv·2022-12-14·CVSS 9.1
CVE-2022-24303 [CRITICAL] pillow-python2 vulnerabilities
pillow-python2 vulnerabilities
USN-5777-1 fixed vulnerabilities in Pillow (Python 3). This update provides the
corresponding updates for Pillow (Python 2) in Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that Pillow incorrectly handled the deletion of temporary
files when using a temporary directory that contains spaces. An attacker could
possibly use this issue to delete arbitrary files. This issue only affected
Ubuntu 20.04 LTS. (CVE-2022-24303)
It was discovered that Pillow incorrectly handled the decompression of highly
compressed GIF data. An attacker could possibly use this issue to cause Pillow
to crash, resulting in a denial of service. (CVE-2022-45198)
OSV
pillow vulnerabilities
osv·2022-12-13·CVSS 9.1
CVE-2022-24303 [CRITICAL] pillow vulnerabilities
pillow vulnerabilities
It was discovered that Pillow incorrectly handled the deletion of temporary
files when using a temporary directory that contains spaces. An attacker could
possibly use this issue to delete arbitrary files. This issue only affected
Ubuntu 20.04 LTS. (CVE-2022-24303)
It was discovered that Pillow incorrectly handled the decompression of highly
compressed GIF data. An attacker could possibly use this issue to cause Pillow
to crash, resulting in a denial of service. (CVE-2022-45198)
GHSA
Pillow vulnerable to Data Amplification attack.
ghsa·2022-11-14
CVE-2022-45198 [HIGH] CWE-409 Pillow vulnerable to Data Amplification attack.
Pillow vulnerable to Data Amplification attack.
Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
OSV
Pillow vulnerable to Data Amplification attack.
osv·2022-11-14
CVE-2022-45198 [HIGH] Pillow vulnerable to Data Amplification attack.
Pillow vulnerable to Data Amplification attack.
Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
OSV
CVE-2022-45198: Pillow before 9
osv·2022-11-14·CVSS 7.5
CVE-2022-45198 [HIGH] CVE-2022-45198: Pillow before 9
Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
CISA ICS
Schneider Electric EcoStruxure Power Operation (Update A)
cisa_ics·2026-02-26·CVSS 9.8
[CRITICAL] Schneider Electric EcoStruxure Power Operation (Update A)
ICS Advisory
##
Schneider Electric EcoStruxure Power Operation (Update A)
Last RevisedFebruary 26, 2026
Alert CodeICSA-25-203-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Successful exploitation of these vulnerabilities could result in the loss of system functionality or unauthorized access to system functions.
The following versions of Schneider Electric EcoStruxure Power Operation (Update A) are affected:
- EcoStruxure Power Operation (EPO) 2022 <=CU6 (CVE-2023-50447, CVE-2024-28219, CVE-2022-45198, CVE-2023-5217, CVE-2023-35945, CVE-2023-44487)
- EcoStruxure Power Operation (EPO) 2024 <=CU1 (CVE-2023-50447, CVE-2024-28219, CVE-2022-45198, CVE-2023-5217, CVE-2023-35945, CVE-2023-44487)
CVS
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2022-12-14·CVSS 9.1
CVE-2022-24303 [CRITICAL] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
USN-5777-1 fixed vulnerabilities in Pillow (Python 3). This update provides the
corresponding updates for Pillow (Python 2) in Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that Pillow incorrectly handled the deletion of temporary
files when using a temporary directory that contains spaces. An attacker could
possibly use this issue to delete arbitrary files. This issue only affected
Ubuntu 20.04 LTS. (CVE-2022-24303)
It was discovered that Pillow incorrectly handled the decompression of highly
compressed GIF data. An attacker could possibly use this issue to cause Pillow
to crash, resulting in a denial of service. (CVE-2022-45198)
Instructions: In general, a standard system update wi
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2022-12-13·CVSS 9.1
CVE-2022-24303 [CRITICAL] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
It was discovered that Pillow incorrectly handled the deletion of temporary
files when using a temporary directory that contains spaces. An attacker could
possibly use this issue to delete arbitrary files. This issue only affected
Ubuntu 20.04 LTS. (CVE-2022-24303)
It was discovered that Pillow incorrectly handled the decompression of highly
compressed GIF data. An attacker could possibly use this issue to cause Pillow
to crash, resulting in a denial of service. (CVE-2022-45198)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2022-45198: pillow - Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Da...
vendor_debian·2022·CVSS 7.5
CVE-2022-45198 [HIGH] CVE-2022-45198: pillow - Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Da...
Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
Scope: local
bookworm: resolved (fixed in 9.2.0-1)
bullseye: resolved (fixed in 8.1.2+dfsg-0.3+deb11u3)
forky: resolved (fixed in 9.2.0-1)
sid: resolved (fixed in 9.2.0-1)
trixie: resolved (fixed in 9.2.0-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.gentoo.org/855683https://cwe.mitre.org/data/definitions/409.htmlhttps://github.com/python-pillow/Pillow/commit/11918eac0628ec8ac0812670d9838361ead2d6a4https://github.com/python-pillow/Pillow/pull/6402https://github.com/python-pillow/Pillow/releases/tag/9.2.0https://security.gentoo.org/glsa/202211-10https://bugs.gentoo.org/855683https://cwe.mitre.org/data/definitions/409.htmlhttps://github.com/python-pillow/Pillow/commit/11918eac0628ec8ac0812670d9838361ead2d6a4https://github.com/python-pillow/Pillow/pull/6402https://github.com/python-pillow/Pillow/releases/tag/9.2.0https://security.gentoo.org/glsa/202211-10
2022-11-14
Published