Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-10994

Опубликовано: 25 июн. 2020
Источник: debian

Описание

In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pillowfixed7.2.0-1package

Примечания

  • https://github.com/python-pillow/Pillow/pull/4505

  • https://github.com/python-pillow/Pillow/pull/4538

  • Fixed in 7.1.0

  • Debian packages are built without JPEG2000 support

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 5 лет назад

In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.

CVSS3: 5.3
redhat
больше 5 лет назад

In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.

CVSS3: 5.5
nvd
больше 5 лет назад

In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.

CVSS3: 5.5
github
больше 5 лет назад

Out-of-bounds reads in Pillow