HIGH 7.5 PyPI

Pillow subject to DoS via SAMPLESPERPIXEL tag

GHSA-q4mp-jvh2-76fj · BIT-pillow-2022-45199 · CVE-2022-45199 · PYSEC-2022-42980

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Pillow starting with 9.2.0 and prior to 9.3.0 allows denial of service via SAMPLESPERPIXEL. A large value in the SAMPLESPERPIXEL tag could lead to a memory and runtime DOS in TiffImagePlugin.py when setting up the context for image decoding. This issue has been patched in version 9.3.0.

Ready to move

Start Securing

Free, no credit card | First findings in minutes