Code Injection in Pillow - CVE-2023-50447

 

Code Injection in Pillow - CVE-2023-50447

Published: January 24, 2024


Vulnerability identifier: #VU85743
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-50447
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation within the PIL.ImageMath.eval function. A remote attacker can send a specially crafted input to the application and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Pillow
Debian Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
Anolis OS
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Python 3 Module
openSUSE Leap
openEuler
Ubuntu
Fedora
EcoStruxure Power Operation
Nautobot
Oracle Financial Services Compliance Studio
Oracle Banking Branch
Oracle Banking Corporate Lending Process Management
Oracle Banking Cash Management
Oracle Banking Origination
Oracle Banking Credit Facilities Process Management
Spectrum Discover
PowerVC
IBM Process Mining
IBM Watson Assistant for IBM Cloud Pak for Data
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Storage Ceph
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
python3x-sqlparse (Red Hat package)
python-sqlparse (Red Hat package)
python3x-pulp-ansible (Red Hat package)
python-pulp-ansible (Red Hat package)
automation-eda-controller (Red Hat package)
ansible-rulebook (Red Hat package)
receptor (Red Hat package)
python3x-pydantic (Red Hat package)
python-pydantic (Red Hat package)
python-pillow-tk
python-pillow-sane
python-pillow-qt
python-pillow-doc
python-pillow-devel
python-pillow
python-pillow (Red Hat package)
ansible-automation-platform-installer (Red Hat package)
ansible-core (Red Hat package)
python3x-requests (Red Hat package)
python-requests (Red Hat package)
python3x-jinja2 (Red Hat package)
python-jinja2 (Red Hat package)
python3x-idna (Red Hat package)
python-idna (Red Hat package)
python3x-aiohttp (Red Hat package)
python-aiohttp (Red Hat package)
python3x-pulpcore (Red Hat package)
python-pulpcore (Red Hat package)
python-Pillow
python-Pillow-debugsource
python-Pillow-debuginfo
automation-controller (Red Hat package)
automation-hub (Red Hat package)
python3x-galaxy-ng (Red Hat package)
python-galaxy-ng (Red Hat package)
python3-pillow
python3-pillow-devel
python3-pillow-tk
python3-pillow-doc
python3x-social-auth-app-django (Red Hat package)
python-social-auth-app-django (Red Hat package)
python3-pil (Ubuntu package)
python3-Pillow-tk-debuginfo
python3-Pillow-tk
python3-Pillow
python3-Pillow-debuginfo
pillow (Debian package)
python-pillow-debuginfo
python-pillow-debugsource
python3-pillow-qt
python3-pillow-help
python311-Pillow-debuginfo
python311-Pillow
python311-Pillow-tk-debuginfo
python311-Pillow-tk
dev-python/pillow
python3x-pillow (Red Hat package)
python3x-gunicorn (Red Hat package)
python-gunicorn (Red Hat package)
python3x-black (Red Hat package)
python-black (Red Hat package)
python3x-pyOpenSSL (Red Hat package)
python-pyOpenSSL (Red Hat package)
python3x-cryptography (Red Hat package)
python-cryptography (Red Hat package)

How to mitigate CVE-2023-50447

Install updates from vendor's website.

Pillow - update to 10.2.0
EcoStruxure Power Operation - update to 2024 CU2
Nautobot - addressed in versions 1.6.11, 2.1.3
Spectrum Discover - update to 2.1.5
Cloud Pak for Network Automation - update to 2.7.2
python3x-sqlparse (Red Hat package) - update to 0.5.0-1.el8ap
python-sqlparse (Red Hat package) - update to 0.5.0-1.el9ap
python3x-pulp-ansible (Red Hat package) - update to 0.20.7-1.el8ap
python-pulp-ansible (Red Hat package) - update to 0.20.7-1.el9ap
automation-eda-controller (Red Hat package) - addressed in versions 1.0.7-1.el8ap, 1.0.7-1.el9ap
ansible-rulebook (Red Hat package) - addressed in versions 1.0.7-1.el8ap, 1.0.7-1.el9ap
receptor (Red Hat package) - addressed in versions 1.4.8-1.el8ap, 1.4.8-1.el9ap
python3x-pydantic (Red Hat package) - update to 1.10.15-1.el8ap
python-pydantic (Red Hat package) - update to 1.10.15-1.el9ap
IBM Process Mining - update to 1.14.4
python-pillow-tk - update to 2.0.0-25.gitd1c6db8
python-pillow-sane - update to 2.0.0-25.gitd1c6db8
python-pillow-qt - update to 2.0.0-25.gitd1c6db8
python-pillow-doc - update to 2.0.0-25.gitd1c6db8
python-pillow-devel - update to 2.0.0-25.gitd1c6db8
python-pillow - update to 2.0.0-25.gitd1c6db8
python-pillow (Red Hat package) - addressed in versions 2.0.0-25.gitd1c6db8.el7_9, 5.1.1-15.el8_2, 5.1.1-15.el8_4, 5.1.1-18.el8_9.1, 5.1.1-19.el8_6, 5.1.1-19.el8_8, 10.3.0-1.el9ap
ansible-automation-platform-installer (Red Hat package) - addressed in versions 2.4-7.1.el8ap, 2.4-7.1.el9ap
ansible-core (Red Hat package) - addressed in versions 2.15.11-1.el8ap, 2.15.11-1.el9ap
python3x-requests (Red Hat package) - update to 2.32.2-1.el8ap
python-requests (Red Hat package) - update to 2.32.2-1.el9ap
python3x-jinja2 (Red Hat package) - update to 3.1.4-1.el8ap
python-jinja2 (Red Hat package) - update to 3.1.4-1.el9ap
python3x-idna (Red Hat package) - update to 3.7-1.el8ap
python-idna (Red Hat package) - update to 3.7-1.el9ap
python3x-aiohttp (Red Hat package) - update to 3.9.5-1.el8ap
python-aiohttp (Red Hat package) - update to 3.9.5-1.el9ap
python3x-pulpcore (Red Hat package) - update to 3.28.27-1.el8ap
python-pulpcore (Red Hat package) - update to 3.28.27-1.el9ap
python-Pillow - addressed in versions 4.2.1-3.26.1, 5.2.0-3.23.1
python-Pillow-debugsource - addressed in versions 4.2.1-3.26.1, 5.2.0-3.23.1, 7.2.0-150300.3.6.1, 9.5.0-150400.5.9.1
python-Pillow-debuginfo - addressed in versions 4.2.1-3.26.1, 5.2.0-3.23.1, 7.2.0-150300.3.6.1, 9.5.0-150400.5.9.1
IBM Cloud Pak for Watson AIOps - update to 4.4.1
automation-controller (Red Hat package) - addressed in versions 4.5.7-1.el8ap, 4.5.7-1.el9ap
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.5
automation-hub (Red Hat package) - addressed in versions 4.9.2-1.el8ap, 4.9.2-1.el9ap
python3x-galaxy-ng (Red Hat package) - update to 4.9.2-1.el8ap
python-galaxy-ng (Red Hat package) - update to 4.9.2-1.el9ap
python3-pillow - addressed in versions 5.1.1-19, 10.2.0-1
python3-pillow-devel - update to 5.1.1-19
python3-pillow-tk - addressed in versions 5.1.1-19, 10.2.0-1
python3-pillow-doc - update to 5.1.1-19
python3x-social-auth-app-django (Red Hat package) - update to 5.4.1-1.el8ap
python-social-auth-app-django (Red Hat package) - update to 5.4.1-1.el9ap
Storage Ceph - update to 6.1z5
python3-pil (Ubuntu package) - addressed in versions 7.0.0-4ubuntu0.8, 9.0.1-1ubuntu0.2, 10.0.0-1ubuntu0.1
python3-Pillow-tk-debuginfo - update to 7.2.0-150300.3.6.1
python3-Pillow-tk - update to 7.2.0-150300.3.6.1
python3-Pillow - update to 7.2.0-150300.3.6.1
python3-Pillow-debuginfo - update to 7.2.0-150300.3.6.1
pillow (Debian package) - addressed in versions 8.1.2+dfsg-0.3+deb11u2, 9.4.0-1.1+deb12u1
python-pillow-debuginfo - update to 9.0.1-6
python-pillow - update to 9.0.1-6
python3-pillow-devel - update to 9.0.1-6
python3-pillow - update to 9.0.1-6
python-pillow-debugsource - update to 9.0.1-6
python3-pillow-tk - update to 9.0.1-6
python3-pillow-qt - update to 9.0.1-6
python3-pillow-help - update to 9.0.1-6
python-pillow - update to 9.4.0-2
python-pillow - update to 9.5.0-3.fc38
python311-Pillow-debuginfo - update to 9.5.0-150400.5.9.1
python311-Pillow - update to 9.5.0-150400.5.9.1
python311-Pillow-tk-debuginfo - update to 9.5.0-150400.5.9.1
python311-Pillow-tk - update to 9.5.0-150400.5.9.1
dev-python/pillow - update to 10.2.0
python3x-pillow (Red Hat package) - update to 10.3.0-1.el8ap
python3x-gunicorn (Red Hat package) - update to 22.0.0-1.el8ap
python-gunicorn (Red Hat package) - update to 22.0.0-1.el9ap
python3x-black (Red Hat package) - update to 22.8.0-2.el8ap
python-black (Red Hat package) - update to 22.8.0-2.el9ap
python3x-pyOpenSSL (Red Hat package) - update to 24.1.0-1.el8ap
python-pyOpenSSL (Red Hat package) - update to 24.1.0-1.el9ap
python3x-cryptography (Red Hat package) - update to 42.0.5-1.el8ap
python-cryptography (Red Hat package) - update to 42.0.5-1.el9ap

External References

Related Security Bulletins