Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE 15 SP6: 2024:1673-2 Critical: Python-Pillow Memory Issues

suse
Calendar Grey June 13, 2024
Dist Suse Esm H88
Important security patch for python-Pillow addresses several vulnerabilities impacting SUSE systems. Update immediately to ensure protection.
* bsc#1180833 * bsc#1183101 * bsc#1183102 * bsc#1183103 * bsc#1183105

Summary

## This update for python-Pillow fixes the following issues: * Fixed ImagePath.Path array handling (bsc#1194552, CVE-2022-22815, bsc#1194551, CVE-2022-22816) * Use snprintf instead of sprintf (bsc#1188574, CVE-2021-34552) * Fix Memory DOS in Icns, Ico and Blp Image Plugins. (bsc#1183110, CVE-2021-27921, bsc#1183108, CVE-2021-27922, bsc#1183107, CVE-2021-27923) * Fix OOB read in SgiRleDecode.c (bsc#1183102, CVE-2021-25293) * Use more specific regex chars to prevent ReDoS (bsc#1183101, CVE-2021-25292) * Fix negative size read in TiffDecode.c (bsc#1183105, CVE-2021-25290) * Raise ValueError if color specifier is too long (bsc#1190229, CVE-2021-23437) * Incorrect error code checking in TiffDecode.c (bsc#1183103, CVE-2021-25289) * OOB Write in TiffDecode.c (bsc#1180833, CVE-2020-35654)

References

* bsc#1180833

* bsc#1183101

* bsc#1183102

* bsc#1183103

* bsc#1183105

* bsc#1183107

* bsc#1183108

* bsc#1183110

* bsc#1188574

* bsc#1190229

* bsc#1194551

* bsc#1194552

Cross-

* CVE-2020-35654

* CVE-2021-23437

* CVE-2021-25289

* CVE-2021-25290

* CVE-2021-25292

* CVE-2021-25293

* CVE-2021-27921

* CVE-2021-27922

* CVE-2021-27923

* CVE-2021-34552

* CVE-2022-22815

* CVE-2022-22816

CVSS scores:

* CVE-2020-35654 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2020-35654 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2021-23437 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2021-23437 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2021-25289 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:1673-2
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here