Description
Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
References (6)
Core 6
Core References
Issue Tracking, Patch, Third Party Advisory
https://bugs.gentoo.org/855683
Third Party Advisory
https://cwe.mitre.org/data/definitions/409.html
Patch, Third Party Advisory
https://github.com/python-pillow/Pillow/commit/11918eac0628ec8ac0812670d9838361ead2d6a4
Patch, Third Party Advisory
https://github.com/python-pillow/Pillow/pull/6402
Release Notes, Third Party Advisory
https://github.com/python-pillow/Pillow/releases/tag/9.2.0
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202211-10
Scores
CVSS v3
7.5
EPSS
0.0032
EPSS Percentile
54.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
Status
published
Products (2)
pypi/pillow
0 - 9.2.0PyPI
python/pillow
< 9.2.0
Published
Nov 14, 2022
Tracked Since
Feb 18, 2026