Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-4009

Опубликовано: 13 апр. 2016
Источник: debian

Описание

Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pillowfixed3.1.1-1package
python-imagingremovedpackage

Примечания

  • https://github.com/python-pillow/Pillow/commit/4e0d9b0b9740d258ade40cce248c93777362ac1e

  • Upstream confirmed that versions prior 2.7 are not vulnerable.

  • https://github.com/python-pillow/Pillow/pull/1714

  • https://github.com/python-pillow/Pillow/issues/1737

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 10 лет назад

Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow.

redhat
почти 10 лет назад

Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow.

CVSS3: 9.8
nvd
почти 10 лет назад

Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow.

CVSS3: 9.8
github
больше 7 лет назад

Pillow Integer overflow in ImagingResampleHorizontal

CVSS3: 9.8
fstec
около 10 лет назад

Уязвимость функции ImagingResampleHorizontal (libImaging/Resample.c) библиотеки для работы с изображениями Pillow, позволяющая нарушителю воздействовать на конфиденциальность, целостность и доступность данных