Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PYSEC-2022-42980: affected range is wrong #118

Closed
G-Rath opened this issue May 17, 2023 · 1 comment · Fixed by #120
Closed

PYSEC-2022-42980: affected range is wrong #118

G-Rath opened this issue May 17, 2023 · 1 comment · Fixed by #120

Comments

@G-Rath
Copy link
Contributor

G-Rath commented May 17, 2023

I'm opening an issue rather than a PR for two reasons: 1. I'm not super familiar with the tooling and am not primarily a Python dev so not sure if it would be enough for me to just edit the advisory via GitHub UI, and 2. it sounds like this database primarily pulls from nvd.nist.gov for which this advisory looks wrong - https://nvd.nist.gov/vuln/detail/CVE-2022-45199 says that it impacts all versions up to v9.3.0 whereas GHSA-q4mp-jvh2-76fj says it only impacts versions between 9.2.0 and 9.3.0 which matches python-pillow/Pillow#6700 which says:

This was introduced in Pillow 9.2.0, found with OSS-Fuzz and fixed by limiting SAMPLESPERPIXEL to the number of planes that we can decode.

oliverchang added a commit that referenced this issue May 26, 2023
oliverchang added a commit that referenced this issue May 26, 2023
* Update PYSEC-2022-42980.yaml

Fixes #118

* Update PYSEC-2022-42980.yaml
@oliverchang
Copy link
Contributor

Thanks for reporting! Sorry for the late response -- I was out and only recently got back.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants