Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-28678

Опубликовано: 02 июн. 2021
Источник: debian

Описание

An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pillowfixed8.2.0-1experimentalpackage
pillowfixed8.1.2+dfsg-0.2package
pillowfixed5.4.1-2+deb10u3busterpackage
pillownot-affectedstretchpackage

Примечания

  • https://pillow.readthedocs.io/en/stable/releasenotes/8.2.0.html#cve-2021-28678-fix-blp-dos

  • https://github.com/python-pillow/Pillow/commit/496245aa4365d0827390bd0b6fbd11287453b3a1

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 4 лет назад

An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.

CVSS3: 7.5
redhat
почти 5 лет назад

An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.

CVSS3: 5.5
nvd
больше 4 лет назад

An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.

CVSS3: 5.5
github
больше 4 лет назад

Insufficient Verification of Data Authenticity in Pillow

suse-cvrf
больше 1 года назад

Security update for python-Pillow