VDB
KO

PYSEC-2022-9

Details

path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / pillow
Introduced in: 0 Fixed in: 9.0.0
Fix pip install --upgrade 'pillow>=9.0.0'

References