Description
Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
References (5)
Core 5
Core References
Issue Tracking, Patch, Third Party Advisory
https://bugs.gentoo.org/878769
Patch, Third Party Advisory
https://github.com/python-pillow/Pillow/commit/2444cddab2f83f28687c7c20871574acbb6dbcf3
Patch, Third Party Advisory
https://github.com/python-pillow/Pillow/pull/6700
Release Notes, Third Party Advisory
https://github.com/python-pillow/Pillow/releases/tag/9.3.0
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202211-10
Scores
CVSS v3
7.5
EPSS
0.0014
EPSS Percentile
33.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-400
Status
published
Products (2)
pypi/pillow
9.2.0 - 9.3.0PyPI
python/pillow
< 9.3.0
Published
Nov 14, 2022
Tracked Since
Feb 18, 2026