CVE-2022-45199
published 2022-11-14CVE-2022-45199: Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
PriorityP432high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.10%
62.0th percentile
Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pillow | < pillow 9.3.0-1 (bookworm) | pillow 9.3.0-1 (bookworm) |
| paloalto | pan-os | — | — |
| python | pillow | < 9.3.0 | 9.3.0 |
| python | pillow | >= 0 < 9.3.0-1 | 9.3.0-1 |
| python | pillow | >= 0 < 9.3.0-1 | 9.3.0-1 |
| python | pillow | >= 0 < 9.3.0-1 | 9.3.0-1 |
| python | pillow | >= 9.2.0 < 9.3.0 | 9.3.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-45199: Pillow before 9
osv·2022-11-14·CVSS 7.5
CVE-2022-45199 [HIGH] CVE-2022-45199: Pillow before 9
Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
GHSA
Pillow subject to DoS via SAMPLESPERPIXEL tag
ghsa·2022-11-14
CVE-2022-45199 [HIGH] CWE-400 Pillow subject to DoS via SAMPLESPERPIXEL tag
Pillow subject to DoS via SAMPLESPERPIXEL tag
Pillow starting with 9.2.0 and prior to 9.3.0 allows denial of service via SAMPLESPERPIXEL. A large value in the SAMPLESPERPIXEL tag could lead to a memory and runtime DOS in TiffImagePlugin.py when setting up the context for image decoding. This issue has been patched in version 9.3.0.
OSV
Pillow subject to DoS via SAMPLESPERPIXEL tag
osv·2022-11-14
CVE-2022-45199 [HIGH] Pillow subject to DoS via SAMPLESPERPIXEL tag
Pillow subject to DoS via SAMPLESPERPIXEL tag
Pillow starting with 9.2.0 and prior to 9.3.0 allows denial of service via SAMPLESPERPIXEL. A large value in the SAMPLESPERPIXEL tag could lead to a memory and runtime DOS in TiffImagePlugin.py when setting up the context for image decoding. This issue has been patched in version 9.3.0.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Pillow) — CVE-2022-45199
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2022-45199 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Reports (Pillow) — CVE-2022-45199
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Pillow) vulnerability
CVE: CVE-2022-45199
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Debian
CVE-2022-45199: pillow - Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
vendor_debian·2022·CVSS 7.5
CVE-2022-45199 [HIGH] CVE-2022-45199: pillow - Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
Scope: local
bookworm: resolved (fixed in 9.3.0-1)
bullseye: resolved
forky: resolved (fixed in 9.3.0-1)
sid: resolved (fixed in 9.3.0-1)
trixie: resolved (fixed in 9.3.0-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.gentoo.org/878769https://github.com/python-pillow/Pillow/commit/2444cddab2f83f28687c7c20871574acbb6dbcf3https://github.com/python-pillow/Pillow/pull/6700https://github.com/python-pillow/Pillow/releases/tag/9.3.0https://security.gentoo.org/glsa/202211-10https://bugs.gentoo.org/878769https://github.com/python-pillow/Pillow/commit/2444cddab2f83f28687c7c20871574acbb6dbcf3https://github.com/python-pillow/Pillow/pull/6700https://github.com/python-pillow/Pillow/releases/tag/9.3.0https://security.gentoo.org/glsa/202211-10
2022-11-14
Published