Resource exhaustion in Pillow - CVE-2022-45199

 

Resource exhaustion in Pillow - CVE-2022-45199

Published: November 22, 2022


Vulnerability identifier: #VU69499
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-45199
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources within the TiffImagePlugin.py when setting up the context for image decoding. A remote attacker can trigger resource exhaustion via a large value in the SAMPLESPERPIXEL tag and perform a denial of service (DoS) attack.


Affected software

Pillow
Gentoo Linux
Oracle Solaris
openEuler
Oracle Banking Trade Finance Process Management
Oracle Banking Branch
Oracle Banking Liquidity Management
Oracle Banking Supply Chain Finance
Oracle Banking Cash Management
Oracle Banking Credit Facilities Process Management
python-pillow
python3-pillow-help
python3-pillow-qt
python-pillow-debuginfo
python-pillow-debugsource
python3-pillow
python3-pillow-devel
python3-pillow-tk
dev-python/pillow

How to mitigate CVE-2022-45199

Install updates from vendor's website.

Pillow - update to 9.3.0
python-pillow - addressed in versions 9.0.1-2, 9.0.1-3
python3-pillow-help - addressed in versions 9.0.1-2, 9.0.1-3
python3-pillow-qt - addressed in versions 9.0.1-2, 9.0.1-3
python-pillow-debuginfo - addressed in versions 9.0.1-2, 9.0.1-3
python-pillow-debugsource - addressed in versions 9.0.1-2, 9.0.1-3
python3-pillow - addressed in versions 9.0.1-2, 9.0.1-3
python3-pillow-devel - addressed in versions 9.0.1-2, 9.0.1-3
python3-pillow-tk - addressed in versions 9.0.1-2, 9.0.1-3
dev-python/pillow - update to 9.3.0

External References

Related Security Bulletins