CVE-2022-22817
10.01.2022, 14:12
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.Enginsight
Vendor | Product | Version |
---|---|---|
python | pillow | 𝑥 < 9.0.1 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
pillow |
| ||||||||||||||||||||||
pillow-python2 |
| ||||||||||||||||||||||
python-imaging |
|
References