Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-9601

Опубликовано: 16 янв. 2015
Источник: debian

Описание

Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pillowfixed2.6.1-2package
python-imagingremovedpackage
python-imagingno-dsawheezypackage
python-imagingno-dsasqueezepackage

Примечания

  • https://github.com/python-pillow/Pillow/commit/b3e09122e527ae554eb590741bbd7611d5710e40

  • http://web.archive.org/web/20150921104441/http://pillow.readthedocs.org:80/releasenotes/2.7.0.html#png-text-chunk-size-limits

Связанные уязвимости

ubuntu
около 11 лет назад

Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.

redhat
около 11 лет назад

Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.

nvd
около 11 лет назад

Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.

CVSS3: 7.5
github
больше 3 лет назад

Pillow denial of service via PNG bomb