CVE-2022-45198Improper Handling of Highly Compressed Data (Data Amplification) in Pillow

Severity
7.5HIGHNVD
OSV9.1
EPSS
0.3%
top 48.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateFeb 26

Description

Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

NVDpython/pillow< 9.2.0
PyPIpython/pillow< 9.2.0
Debianpython/pillow< 8.1.2+dfsg-0.3+deb11u3+3
Ubuntupython/pillow< 7.0.0-4ubuntu0.7+1
Palo Altopaloalto/pan-os

Patches

🔴Vulnerability Details

6
OSV
pillow-python2 vulnerabilities2022-12-14
OSV
pillow vulnerabilities2022-12-13
GHSA
Pillow vulnerable to Data Amplification attack.2022-11-14
OSV
Pillow vulnerable to Data Amplification attack.2022-11-14
CVEList
CVE-2022-45198: Pillow before 92022-11-14

📋Vendor Advisories

5
CISA ICS
Schneider Electric EcoStruxure Power Operation (Update A)2026-02-26
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
Ubuntu
Pillow vulnerabilities2022-12-14
Ubuntu
Pillow vulnerabilities2022-12-13
Debian
CVE-2022-45198: pillow - Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Da...2022
CVE-2022-45198 — Python Pillow vulnerability | cvebase