Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-27922

Опубликовано: 03 мар. 2021
Источник: debian

Описание

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pillowfixed8.1.2-1package
pillowfixed5.4.1-2+deb10u3busterpackage
pillowignoredstretchpackage

Примечания

  • https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html

  • https://github.com/python-pillow/Pillow/commit/756fff33128a0b643d10518a26ad04b726dd8973

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.

CVSS3: 7.5
redhat
почти 5 лет назад

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.

CVSS3: 7.5
nvd
почти 5 лет назад

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.

CVSS3: 7.5
github
почти 5 лет назад

Pillow Uncontrolled Resource Consumption

suse-cvrf
больше 1 года назад

Security update for python-Pillow