cbcvebase.
CVE-2022-45198
published 2022-11-14

CVE-2022-45198: Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).

Affected

10 ranges
VendorProductVersion rangeFixed in
debianpillow< pillow 9.2.0-1 (bookworm)pillow 9.2.0-1 (bookworm)
paloaltopan-os
pythonpillow< 9.2.09.2.0
pythonpillow>= 0 < 8.1.2+dfsg-0.3+deb11u38.1.2+dfsg-0.3+deb11u3
pythonpillow>= 0 < 9.2.0-19.2.0-1
pythonpillow>= 0 < 9.2.0-19.2.0-1
pythonpillow>= 0 < 9.2.0-19.2.0-1
pythonpillow>= 0 < 9.2.09.2.0
pythonpillow>= 0 < 7.0.0-4ubuntu0.77.0.0-4ubuntu0.7
pythonpillow>= 0 < 9.0.1-1ubuntu0.19.0.1-1ubuntu0.1

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv9.1CRITICAL