VDB

PYSEC-2022-9

PYSEC-2022-9 PUBLISHED

path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.

Affected Products

VendorProductVersions
PyPIpillow0, 1.0, 1.2

Timeline

  • Jan 10, 2022 CVE Published
  • Dec 6, 2023 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›