Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-22jr-vc7j-g762

Опубликовано: 16 мар. 2020
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Potential buffer overflow in psd-tools

Impact

An issue was discovered in psd-tools before 1.9.4. The Cython implementation of RLE decoding did not check for malformed PSD input data during decoding to the PIL.Image or NumPy format, leading to a Buffer Overflow.

Patches

Users of psd-tools version v1.8.37 to v1.9.3 should upgrade to v1.9.4.

Workarounds

Without Cython present on installation, buffer overflow does not occur but IndexError will be thrown. However, already installed psd-tools with Cython extention should be upgraded.

References

https://github.com/psd-tools/psd-tools/pull/198

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

psd-tools

pip
Затронутые версииВерсия исправления

>= 1.8.37, < 1.9.3

1.9.4

EPSS

Процентиль: 61%
0.00418
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-754

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

An issue was discovered in psd-tools before 1.9.4. The Cython implementation of RLE decoding did not check for malicious data.

EPSS

Процентиль: 61%
0.00418
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-754