CVE-2022-45199Uncontrolled Resource Consumption in Pillow

Severity
7.5HIGHNVD
EPSS
0.1%
top 68.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateFeb 14

Description

Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDpython/pillow< 9.3.0
PyPIpython/pillow9.2.09.3.0
Debianpython/pillow< 9.3.0-1+2
Palo Altopaloalto/pan-os

Patches

🔴Vulnerability Details

4
OSV
CVE-2022-45199: Pillow before 92022-11-14
GHSA
Pillow subject to DoS via SAMPLESPERPIXEL tag2022-11-14
OSV
Pillow subject to DoS via SAMPLESPERPIXEL tag2022-11-14
CVEList
CVE-2022-45199: Pillow before 92022-11-14

📋Vendor Advisories

3
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Pillow) — CVE-2022-451992023-07-15
Debian
CVE-2022-45199: pillow - Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.2022
CVE-2022-45199 — Uncontrolled Resource Consumption | cvebase