Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).

Project Subscriptions

Vendors Products
Debian Linux Subscribe
Ansible Automation Platform Subscribe
Enterprise Linux Subscribe
Rhel Aus Subscribe
Rhel E4s Subscribe
Rhel Eus Subscribe
Rhel Tus Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3724-1 pillow security update
Debian DSA Debian DSA DSA-5704-1 pillow security update
Github GHSA Github GHSA GHSA-3f63-hfp8-52jq Arbitrary Code Execution in Pillow
Ubuntu USN Ubuntu USN USN-6618-1 Pillow vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T22:16:46.654Z

Reserved: 2023-12-10T00:00:00

Link: CVE-2023-50447

cve-icon Vulnrichment

Updated: 2024-08-02T22:16:46.654Z

cve-icon NVD

Status : Modified

Published: 2024-01-19T20:15:11.870

Modified: 2024-11-21T08:37:00.967

Link: CVE-2023-50447

cve-icon Redhat

Severity : Important

Publid Date: 2024-01-19T00:00:00Z

Links: CVE-2023-50447 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses