Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-16865

Опубликовано: 04 окт. 2019
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pillowfixed6.2.0-1package
pillowfixed5.4.1-2+deb10u1busterpackage
pillowignoredstretchpackage
pillowignoredjessiepackage
python-imagingremovedpackage

Примечания

  • https://github.com/python-pillow/Pillow/commit/b36c1bc943d554ba223086c7efb502d080f73905

  • https://github.com/python-pillow/Pillow/commit/f228d0ccbf6bf9392d7fcd51356ef2cfda80c75a

  • https://github.com/python-pillow/Pillow/commit/b9693a51c99c260bd66d1affeeab4a226cf7e5a5

  • https://github.com/python-pillow/Pillow/commit/cc16025e234b7a7a4dd3a86d2fdc0980698db9cc

EPSS

Процентиль: 90%
0.05198
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

CVSS3: 7.5
redhat
больше 6 лет назад

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

CVSS3: 7.5
nvd
больше 6 лет назад

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

CVSS3: 7.5
github
больше 6 лет назад

DOS attack in Pillow when processing specially crafted image files

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость библиотеки для работы с изображениями Pillow, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 90%
0.05198
Низкий