Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-28676

Опубликовано: 02 июн. 2021
Источник: debian

Описание

An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pillowfixed8.2.0-1experimentalpackage
pillowfixed8.1.2+dfsg-0.2package
pillowignoredbusterpackage

Примечания

  • https://pillow.readthedocs.io/en/stable/releasenotes/8.2.0.html#cve-2021-28676-fix-fli-dos

  • https://github.com/python-pillow/Pillow/commit/bb6c11fb889e6c11b0ee122b828132ee763b5856

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load.

CVSS3: 7.5
redhat
почти 5 лет назад

An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load.

CVSS3: 7.5
nvd
больше 4 лет назад

An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load.

CVSS3: 7.5
github
больше 4 лет назад

Potential infinite loop in Pillow

CVSS3: 7.5
fstec
почти 5 лет назад

Уязвимость компонента FliDecode библиотеки для работы с изображениями Pillow, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании