Wind River Support Network

HomeDefectsLIN1021-2371
Fixed

LIN1021-2371 : Security Advisory - python3-pillow - CVE-2022-22817

Created: Jan 8, 2022    Updated: Feb 7, 2022
Resolved Date: Feb 7, 2022
Found In Version: 10.21.20.1
Fix Version: 10.21.20.10
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method.

https://nvd.nist.gov/vuln/detail/CVE-2022-22817

CVEs


Live chat
Online