Bugzilla – Bug 1199713
VUL-0: CVE-2022-30595: python-Pillow: heap buffer overflow in crafted TGA file
Last modified: 2024-10-17 22:25:30 UTC
From https://github.com/python-pillow/Pillow/releases/tag/9.1.1: CVE-2022-30595: When reading a TGA file with RLE packets that cross scan lines, Pillow reads the information past the end of the first line without deducting that from the length of the remaining file data. This vulnerability was introduced in Pillow 9.1.0, and can cause a heap buffer overflow. References: https://github.com/python-pillow/Pillow/releases/tag/9.1.1 https://bugzilla.redhat.com/show_bug.cgi?id=2087609 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-30595
nly openSUSE:Factory is affected, please update to 9.1.1
submitted to factory
This is an autogenerated message for OBS integration: This bug (1199713) was mentioned in https://build.opensuse.org/request/show/979708 Factory / python-Pillow
landed