Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9189

Опубликовано: 04 нояб. 2016
Источник: debian
EPSS Низкий

Описание

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pillowfixed3.4.2-1package
python-imagingremovedpackage

Примечания

  • https://github.com/python-pillow/Pillow/issues/2105

  • https://github.com/python-pillow/Pillow/pull/2146/commits/c50ebe6459a131a1ea8ca531f10da616d3ceaa0f

EPSS

Процентиль: 57%
0.00358
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 9 лет назад

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

CVSS3: 6.5
redhat
больше 9 лет назад

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

CVSS3: 5.5
nvd
больше 9 лет назад

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

CVSS3: 5.5
github
больше 7 лет назад

Pillow Integer overflow in Map.c

EPSS

Процентиль: 57%
0.00358
Низкий