Описание
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| pillow | fixed | 8.1.2-1 | package | |
| pillow | fixed | 5.4.1-2+deb10u3 | buster | package |
| pillow | ignored | stretch | package |
Примечания
https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html
https://github.com/python-pillow/Pillow/commit/756fff33128a0b643d10518a26ad04b726dd8973
EPSS
Связанные уязвимости
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
Pillow Denial of Service by Uncontrolled Resource Consumption
EPSS