VDB
PYSEC-2022-42979
PYSEC-2022-42979
PUBLISHED
Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PyPI | pillow | 2.1.0, 1.1, 1.2 |
Timeline
- Nov 14, 2022 CVE Published
- Jun 10, 2026 CVE Updated
References
- https://bugs.gentoo.org/855683 url
- https://github.com/python-pillow/Pillow/commit/11918eac0628ec8ac0812670d9838361ead2d6a4 patch
- https://github.com/python-pillow/Pillow/pull/6402 url
- https://github.com/python-pillow/Pillow/releases/tag/9.2.0 url
- https://cwe.mitre.org/data/definitions/409.html url
- https://github.com/advisories/GHSA-m2vv-5vj5-2hm7 advisory