Bug 1199713 (CVE-2022-30595) - VUL-0: CVE-2022-30595: python-Pillow: heap buffer overflow in crafted TGA file
Summary: VUL-0: CVE-2022-30595: python-Pillow: heap buffer overflow in crafted TGA file
Status: RESOLVED FIXED
Alias: CVE-2022-30595
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Dirk Mueller
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/332312/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-05-19 12:56 UTC by Gabriele Sonnu
Modified: 2024-10-17 22:25 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Gabriele Sonnu 2022-05-19 12:56:00 UTC
From https://github.com/python-pillow/Pillow/releases/tag/9.1.1:

CVE-2022-30595: When reading a TGA file with RLE packets that cross scan lines, Pillow reads the information past the end of the first line without deducting that from the length of the remaining file data. This vulnerability was introduced in Pillow 9.1.0, and can cause a heap buffer overflow.

References:
https://github.com/python-pillow/Pillow/releases/tag/9.1.1
https://bugzilla.redhat.com/show_bug.cgi?id=2087609
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-30595
Comment 1 Gabriele Sonnu 2022-05-19 12:57:20 UTC
nly openSUSE:Factory is affected, please update to 9.1.1
Comment 2 Dirk Mueller 2022-05-29 18:43:07 UTC
submitted to factory
Comment 3 OBSbugzilla Bot 2022-05-29 20:40:02 UTC
This is an autogenerated message for OBS integration:
This bug (1199713) was mentioned in
https://build.opensuse.org/request/show/979708 Factory / python-Pillow
Comment 4 Dirk Mueller 2022-05-31 09:11:48 UTC
landed