Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-28678

Опубликовано: 02 июн. 2021
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pillowfixed8.2.0-1experimentalpackage
pillowfixed8.1.2+dfsg-0.2package
pillowfixed5.4.1-2+deb10u3busterpackage
pillownot-affectedstretchpackage

Примечания

  • https://pillow.readthedocs.io/en/stable/releasenotes/8.2.0.html#cve-2021-28678-fix-blp-dos

  • https://github.com/python-pillow/Pillow/commit/496245aa4365d0827390bd0b6fbd11287453b3a1

EPSS

Процентиль: 29%
0.0011
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 5 лет назад

An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.

CVSS3: 7.5
redhat
около 5 лет назад

An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.

CVSS3: 5.5
nvd
почти 5 лет назад

An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.

CVSS3: 5.5
github
почти 5 лет назад

Insufficient Verification of Data Authenticity in Pillow

suse-cvrf
почти 2 года назад

Security update for python-Pillow

EPSS

Процентиль: 29%
0.0011
Низкий