Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-27922

Опубликовано: 03 мар. 2021
Источник: debian
EPSS Низкий

Описание

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pillowfixed8.1.2-1package
pillowfixed5.4.1-2+deb10u3busterpackage
pillowignoredstretchpackage

Примечания

  • https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html

  • https://github.com/python-pillow/Pillow/commit/756fff33128a0b643d10518a26ad04b726dd8973

EPSS

Процентиль: 35%
0.00145
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.

CVSS3: 7.5
redhat
около 5 лет назад

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.

CVSS3: 7.5
nvd
около 5 лет назад

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.

CVSS3: 7.5
github
около 5 лет назад

Pillow Uncontrolled Resource Consumption

suse-cvrf
почти 2 года назад

Security update for python-Pillow

EPSS

Процентиль: 35%
0.00145
Низкий