Resource management error in Pillow - CVE-2022-45198
Published: November 22, 2022
Vulnerability identifier: #VU69498
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-45198
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources when handing highly compressed GIF data. A remote attacker can pass specially crafted GIF file to the application and perform a denial of service (DoS) attack.
Affected software
Pillow
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
openSUSE Leap
openEuler
Ubuntu
EcoStruxure Power Operation
python3-pil (Ubuntu package)
python3-Pillow-tk-debuginfo
python3-Pillow-tk
python3-Pillow-debuginfo
python3-Pillow
python-Pillow-debugsource
python-Pillow-debuginfo
python-pillow-debuginfo
python3-pillow-help
python3-pillow-tk
python-pillow-debugsource
python3-pillow
python3-pillow-qt
python3-pillow-devel
python-pillow
dev-python/pillow
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
openSUSE Leap
openEuler
Ubuntu
EcoStruxure Power Operation
python3-pil (Ubuntu package)
python3-Pillow-tk-debuginfo
python3-Pillow-tk
python3-Pillow-debuginfo
python3-Pillow
python-Pillow-debugsource
python-Pillow-debuginfo
python-pillow-debuginfo
python3-pillow-help
python3-pillow-tk
python-pillow-debugsource
python3-pillow
python3-pillow-qt
python3-pillow-devel
python-pillow
dev-python/pillow
How to mitigate CVE-2022-45198
Install updates from vendor's website.
Pillow - update to 9.2.0
EcoStruxure Power Operation - update to 2024 CU2
python3-pil (Ubuntu package) - addressed in versions 7.0.0-4ubuntu0.7, 9.0.1-1ubuntu0.1
python3-Pillow-tk-debuginfo - update to 7.2.0-150300.3.18.1
python3-Pillow-tk - update to 7.2.0-150300.3.18.1
python3-Pillow-debuginfo - update to 7.2.0-150300.3.18.1
python3-Pillow - update to 7.2.0-150300.3.18.1
python-Pillow-debugsource - update to 7.2.0-150300.3.18.1
python-Pillow-debuginfo - update to 7.2.0-150300.3.18.1
python-pillow-debuginfo - update to 9.0.1-5
python3-pillow-help - update to 9.0.1-5
python3-pillow-tk - update to 9.0.1-5
python-pillow-debugsource - update to 9.0.1-5
python3-pillow - update to 9.0.1-5
python3-pillow-qt - update to 9.0.1-5
python3-pillow-devel - update to 9.0.1-5
python-pillow - update to 9.0.1-5
dev-python/pillow - update to 9.3.0
EcoStruxure Power Operation - update to 2024 CU2
python3-pil (Ubuntu package) - addressed in versions 7.0.0-4ubuntu0.7, 9.0.1-1ubuntu0.1
python3-Pillow-tk-debuginfo - update to 7.2.0-150300.3.18.1
python3-Pillow-tk - update to 7.2.0-150300.3.18.1
python3-Pillow-debuginfo - update to 7.2.0-150300.3.18.1
python3-Pillow - update to 7.2.0-150300.3.18.1
python-Pillow-debugsource - update to 7.2.0-150300.3.18.1
python-Pillow-debuginfo - update to 7.2.0-150300.3.18.1
python-pillow-debuginfo - update to 9.0.1-5
python3-pillow-help - update to 9.0.1-5
python3-pillow-tk - update to 9.0.1-5
python-pillow-debugsource - update to 9.0.1-5
python3-pillow - update to 9.0.1-5
python3-pillow-qt - update to 9.0.1-5
python3-pillow-devel - update to 9.0.1-5
python-pillow - update to 9.0.1-5
dev-python/pillow - update to 9.3.0