Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-3444

Опубликовано: 31 июл. 2012
Источник: debian
EPSS Низкий

Описание

The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-djangofixed1.4.1-1package

Примечания

  • https://www.djangoproject.com/weblog/2012/jul/30/security-releases-issued/

  • https://www.openwall.com/lists/oss-security/2012/07/31/1

  • https://www.openwall.com/lists/oss-security/2012/07/31/2

EPSS

Процентиль: 78%
0.0119
Низкий

Связанные уязвимости

ubuntu
почти 13 лет назад

The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image.

nvd
почти 13 лет назад

The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image.

CVSS3: 7.5
github
около 3 лет назад

Django vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer

EPSS

Процентиль: 78%
0.0119
Низкий