Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2024/01/20/1 | Mailing List Third Party Advisory |
https://devhub.checkmarx.com/cve-details/CVE-2023-50447/ | Third Party Advisory |
https://duartecsantos.github.io/2024-01-02-CVE-2023-50447/ | |
https://github.com/python-pillow/Pillow/releases | Release Notes |
https://lists.debian.org/debian-lts-announce/2024/01/msg00019.html | Mailing List Third Party Advisory |
Configurations
History
01 Aug 2024, 13:45
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-95 |
27 Mar 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
15 Feb 2024, 03:18
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | |
First Time |
Debian
Debian debian Linux |
|
References | () https://lists.debian.org/debian-lts-announce/2024/01/msg00019.html - Mailing List, Third Party Advisory |
29 Jan 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
26 Jan 2024, 13:50
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
First Time |
Python pillow
Python |
|
CPE | cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:* | |
CWE | CWE-94 | |
References | () https://duartecsantos.github.io/2023-01-02-CVE-2023-50447/ - Exploit, Third Party Advisory | |
References | () http://www.openwall.com/lists/oss-security/2024/01/20/1 - Mailing List, Third Party Advisory | |
References | () https://github.com/python-pillow/Pillow/releases - Release Notes | |
References | () https://devhub.checkmarx.com/cve-details/CVE-2023-50447/ - Third Party Advisory |
20 Jan 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
19 Jan 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-19 20:15
Updated : 2024-08-01 13:45
NVD link : CVE-2023-50447
Mitre link : CVE-2023-50447
CVE.ORG link : CVE-2023-50447
JSON object : View
Products Affected
debian
- debian_linux
python
- pillow