7.5
CVE-2022-45199
- EPSS 1.11%
- Veröffentlicht 14.11.2022 07:15:10
- Zuletzt bearbeitet 21.11.2024 07:28:57
- Erkennungen
Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.11% | 0.628 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
https://security.gentoo.org/glsa/202211-10
https://bugs.gentoo.org/878769
https://github.com/python-pillow/Pillow/commit/2444cddab2f83f28687c7c20871574acbb6dbcf3
https://github.com/python-pillow/Pillow/pull/6700
https://github.com/python-pillow/Pillow/releases/tag/9.3.0