CVE-2023-50447
published 2024-01-19CVE-2023-50447: Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which…
PriorityP349high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.70%
74.6th percentile
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | pillow | < pillow 9.4.0-1.1+deb12u1 (bookworm) | pillow 9.4.0-1.1+deb12u1 (bookworm) |
| paloalto | pan-os | — | — |
| python | pillow | <= 10.1.0 | — |
| python | pillow | >= 0 < 8.1.2+dfsg-0.3+deb11u2 | 8.1.2+dfsg-0.3+deb11u2 |
| python | pillow | >= 0 < 9.4.0-1.1+deb12u1 | 9.4.0-1.1+deb12u1 |
| python | pillow | >= 0 < 10.2.0-1 | 10.2.0-1 |
| python | pillow | >= 0 < 10.2.0-1 | 10.2.0-1 |
| python | pillow | >= 0 < 10.2.0 | 10.2.0 |
| python | pillow | >= 0 < 7.0.0-4ubuntu0.8 | 7.0.0-4ubuntu0.8 |
| python | pillow | >= 0 < 9.0.1-1ubuntu0.2 | 9.0.1-1ubuntu0.2 |
| python | pillow | >= 0 < 2.3.0-1ubuntu3.4+esm5 | 2.3.0-1ubuntu3.4+esm5 |
| python | pillow | >= 0 < 3.1.2-0ubuntu1.6+esm3 | 3.1.2-0ubuntu1.6+esm3 |
| python | pillow | >= 0 < 5.1.0-1ubuntu0.8+esm2 | 5.1.0-1ubuntu0.8+esm2 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.1CRITICAL
vendor_oracle8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2026-03-31·CVSS 9.1
CVE-2023-50447 [CRITICAL] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
It was discovered that Pillow did not correctly handle reading J2K files,
which could lead to an out-of-bounds read vulnerability. If a user or
automated system were tricked into opening a specially crafted file, an
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 16.04 LTS. (CVE-2021-25287, CVE-2021-25288)
It was discovered that Pillow did not correctly handle certain integer
arithmetic, which could lead to a buffer overflow. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS. (CVE-2021-25290)
It was discovered that Pillow did not correctly perform bounds checkin
CISA ICS
Schneider Electric EcoStruxure Power Operation (Update A)
cisa_ics·2026-02-26·CVSS 9.8
[CRITICAL] Schneider Electric EcoStruxure Power Operation (Update A)
ICS Advisory
##
Schneider Electric EcoStruxure Power Operation (Update A)
Last RevisedFebruary 26, 2026
Alert CodeICSA-25-203-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Successful exploitation of these vulnerabilities could result in the loss of system functionality or unauthorized access to system functions.
The following versions of Schneider Electric EcoStruxure Power Operation (Update A) are affected:
- EcoStruxure Power Operation (EPO) 2022 <=CU6 (CVE-2023-50447, CVE-2024-28219, CVE-2022-45198, CVE-2023-5217, CVE-2023-35945, CVE-2023-44487)
- EcoStruxure Power Operation (EPO) 2024 <=CU1 (CVE-2023-50447, CVE-2024-28219, CVE-2022-45198, CVE-2023-5217, CVE-2023-35945, CVE-2023-44487)
CVS
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Pillow) — CVE-2023-50447
vendor_oracle·2024-10-15·CVSS 8.1
CVE-2023-50447 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Reports (Pillow) — CVE-2023-50447
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Pillow) vulnerability
CVE: CVE-2023-50447
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Pillow) — CVE-2023-50447
vendor_oracle·2024-07-15·CVSS 8.1
CVE-2023-50447 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Reports (Pillow) — CVE-2023-50447
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Pillow) vulnerability
CVE: CVE-2023-50447
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2024-01-30·CVSS 7.5
CVE-2023-44271 [HIGH] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
It was discovered that Pillow incorrectly handled certain long text
arguments. An attacker could possibly use this issue to cause Pillow to
consume resources, leading to a denial of service. This issue only affected
Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2023-44271)
Duarte Santos discovered that Pillow incorrectly handled the environment
parameter to PIL.ImageMath.eval. An attacker could possibly use this issue
to execute arbitrary code. (CVE-2023-50447)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
pillow: Arbitrary Code Execution via the environment parameter
vendor_redhat·2024-01-19·CVSS 9.8
CVE-2023-50447 [CRITICAL] CWE-77 pillow: Arbitrary Code Execution via the environment parameter
pillow: Arbitrary Code Execution via the environment parameter
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
A vulnerability was found in Pillow, a popular Python imaging library. The flaw identified in the PIL.ImageMath.eval function enables arbitrary code execution by manipulating the environment parameter.
Statement: The vulnerability in Pillow's PIL.ImageMath.eval function poses a significant threat due to its potential for arbitrary code execution. Pillow's widespread use in diverse domains makes this flaw particularly impactful, as it could lead to unauthorized access, data breaches, and compromise of entire systems. The complex exploi
Debian
CVE-2023-50447: pillow - Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the...
vendor_debian·2023·CVSS 9.8
CVE-2023-50447 [CRITICAL] CVE-2023-50447: pillow - Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the...
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
Scope: local
bookworm: resolved (fixed in 9.4.0-1.1+deb12u1)
bullseye: resolved (fixed in 8.1.2+dfsg-0.3+deb11u2)
forky: resolved (fixed in 10.2.0-1)
sid: resolved (fixed in 10.2.0-1)
trixie: resolved (fixed in 10.2.0-1)
OSV
pillow vulnerabilities
osv·2026-03-31·CVSS 9.1
CVE-2021-25287 [CRITICAL] pillow vulnerabilities
pillow vulnerabilities
It was discovered that Pillow did not correctly handle reading J2K files,
which could lead to an out-of-bounds read vulnerability. If a user or
automated system were tricked into opening a specially crafted file, an
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 16.04 LTS. (CVE-2021-25287, CVE-2021-25288)
It was discovered that Pillow did not correctly handle certain integer
arithmetic, which could lead to a buffer overflow. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS. (CVE-2021-25290)
It was discovered that Pillow did not correctly perform bounds checking
for certain operations. An attacker could possibly use this i
OSV
pillow vulnerabilities
osv·2024-01-30·CVSS 7.5
CVE-2023-44271 [HIGH] pillow vulnerabilities
pillow vulnerabilities
It was discovered that Pillow incorrectly handled certain long text
arguments. An attacker could possibly use this issue to cause Pillow to
consume resources, leading to a denial of service. This issue only affected
Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2023-44271)
Duarte Santos discovered that Pillow incorrectly handled the environment
parameter to PIL.ImageMath.eval. An attacker could possibly use this issue
to execute arbitrary code. (CVE-2023-50447)
GHSA
Arbitrary Code Execution in Pillow
ghsa·2024-01-19·CVSS 9.8
CVE-2023-50447 [CRITICAL] CWE-94 Arbitrary Code Execution in Pillow
Arbitrary Code Execution in Pillow
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
OSV
Arbitrary Code Execution in Pillow
osv·2024-01-19·CVSS 9.8
CVE-2023-50447 [CRITICAL] Arbitrary Code Execution in Pillow
Arbitrary Code Execution in Pillow
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
OSV
CVE-2023-50447: Pillow through 10
osv·2024-01-19·CVSS 9.8
CVE-2023-50447 [CRITICAL] CVE-2023-50447: Pillow through 10
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2024/01/20/1https://devhub.checkmarx.com/cve-details/CVE-2023-50447/https://duartecsantos.github.io/2024-01-02-CVE-2023-50447/https://github.com/python-pillow/Pillow/releaseshttps://lists.debian.org/debian-lts-announce/2024/01/msg00019.htmlhttp://www.openwall.com/lists/oss-security/2024/01/20/1https://devhub.checkmarx.com/cve-details/CVE-2023-50447/https://duartecsantos.github.io/2024-01-02-CVE-2023-50447/https://github.com/python-pillow/Pillow/releaseshttps://lists.debian.org/debian-lts-announce/2024/01/msg00019.html
2024-01-19
Published