CVE-2022-22817
10.01.2022, 14:12
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.Enginsight
| Vendor | Product | Version |
|---|---|---|
| python | pillow | 𝑥 < 9.0.1 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| pillow |
| ||||||||||||||||||||||
| pillow-python2 |
| ||||||||||||||||||||||
| python-imaging |
|
References