Resource management error in Pillow - CVE-2022-45198

 

Resource management error in Pillow - CVE-2022-45198

Published: November 22, 2022


Vulnerability identifier: #VU69498
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-45198
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources when handing highly compressed GIF data. A remote attacker can pass specially crafted GIF file to the application and perform a denial of service (DoS) attack.


Affected software

Pillow
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
openSUSE Leap
openEuler
Ubuntu
EcoStruxure Power Operation
python3-pil (Ubuntu package)
python3-Pillow-tk-debuginfo
python3-Pillow-tk
python3-Pillow-debuginfo
python3-Pillow
python-Pillow-debugsource
python-Pillow-debuginfo
python-pillow-debuginfo
python3-pillow-help
python3-pillow-tk
python-pillow-debugsource
python3-pillow
python3-pillow-qt
python3-pillow-devel
python-pillow
dev-python/pillow

How to mitigate CVE-2022-45198

Install updates from vendor's website.

Pillow - update to 9.2.0
EcoStruxure Power Operation - update to 2024 CU2
python3-pil (Ubuntu package) - addressed in versions 7.0.0-4ubuntu0.7, 9.0.1-1ubuntu0.1
python3-Pillow-tk-debuginfo - update to 7.2.0-150300.3.18.1
python3-Pillow-tk - update to 7.2.0-150300.3.18.1
python3-Pillow-debuginfo - update to 7.2.0-150300.3.18.1
python3-Pillow - update to 7.2.0-150300.3.18.1
python-Pillow-debugsource - update to 7.2.0-150300.3.18.1
python-Pillow-debuginfo - update to 7.2.0-150300.3.18.1
python-pillow-debuginfo - update to 9.0.1-5
python3-pillow-help - update to 9.0.1-5
python3-pillow-tk - update to 9.0.1-5
python-pillow-debugsource - update to 9.0.1-5
python3-pillow - update to 9.0.1-5
python3-pillow-qt - update to 9.0.1-5
python3-pillow-devel - update to 9.0.1-5
python-pillow - update to 9.0.1-5
dev-python/pillow - update to 9.3.0

External References

Related Security Bulletins