CVE-2022-24303
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
02 / AFFECTED SOFTWARE
Affected packages
44 explicit affected versions
85 explicit affected versions
85 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24303.json
- https://github.com/python-pillow/Pillow/pull/3450
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W4ZUXPKEX72O3E5IHBPVY5ZCPMJ4GHHV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XR6UP2XONXOVXI4446VY72R63YRO2YTP/
- https://nvd.nist.gov/vuln/detail/CVE-2022-24303
- https://pillow.readthedocs.io/en/stable/releasenotes/9.0.1.html#security
- https://security.gentoo.org/glsa/202211-10
- https://github.com/advisories/GHSA-9j59-75qj-795w
- https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2022-168.yaml
- https://github.com/python-pillow/Pillow
- https://github.com/python-pillow/Pillow/blob/e8ab5640774716c5486d3cb05167f74f742ad6ef/CHANGES.rst?plain=1#L1172
- https://github.com/python-pillow/Pillow/commit/10c4f75aaa383bd9671e923e3b91d391ea12d781
- https://github.com/python-pillow/Pillow/commit/143032103c9f2d55a0a7960bd3e630cb72549e8a
- https://github.com/python-pillow/Pillow/commit/427221ef5f19157001bf8b1ad7cfe0b905ca8c26
- https://github.com/python-pillow/Pillow/pull/6010
- https://lists.fedoraproject.org/archives/list/[email protected]/message/W4ZUXPKEX72O3E5IHBPVY5ZCPMJ4GHHV
- https://lists.fedoraproject.org/archives/list/[email protected]/message/XR6UP2XONXOVXI4446VY72R63YRO2YTP