RHSA-2022:0609
Vulnerability Summary
Timeline
Description
Red Hat Security Advisory: python-pillow security update
CVSS Metrics
- v3.1•CRITICAL•Score: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- redhat•python-pillow
< 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9
- redhat•python-pillow-debuginfo
< 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9
- redhat•python-pillow-devel
< 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9
- redhat•python-pillow-doc
< 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9
- redhat•python-pillow-qt
< 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9
- redhat•python-pillow-sane
< 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9
- redhat•python-pillow-tk
< 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9 | < 0:2.0.0-23.gitd1c6db8.el7_9
References (12)
- https://access.redhat.com/errata/RHSA-2022:0609
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2042522
- https://bugzilla.redhat.com/show_bug.cgi?id=2042527
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_0609.json
- https://access.redhat.com/security/cve/CVE-2022-22816
- https://www.cve.org/CVERecord?id=CVE-2022-22816
- https://nvd.nist.gov/vuln/detail/CVE-2022-22816
- https://pillow.readthedocs.io/en/stable/releasenotes/9.0.0.html#fixed-imagepath-path-array-handling
- https://access.redhat.com/security/cve/CVE-2022-22817
- https://www.cve.org/CVERecord?id=CVE-2022-22817
- https://nvd.nist.gov/vuln/detail/CVE-2022-22817