Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-2533

Опубликовано: 13 апр. 2016
Источник: debian
EPSS Низкий

Описание

Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pillowfixed3.1.1-1package
python-imagingremovedpackage
python-imagingfixed1.1.7-4+deb7u2wheezypackage

Примечания

  • https://github.com/python-pillow/Pillow/pull/1706

  • https://www.openwall.com/lists/oss-security/2016/02/02/5

  • https://github.com/python-pillow/Pillow/commit/ae453aa18b66af54e7ff716f4ccb33adca60afd4

EPSS

Процентиль: 79%
0.01278
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 10 лет назад

Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.

redhat
почти 12 лет назад

Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.

CVSS3: 6.5
nvd
почти 10 лет назад

Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.

CVSS3: 6.5
github
больше 7 лет назад

Pillow buffer overflow in ImagingPcdDecode

EPSS

Процентиль: 79%
0.01278
Низкий