Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3c5c-7235-994j

Опубликовано: 24 июл. 2018
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Pillow buffer overflow in ImagingPcdDecode

Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.

Пакеты

Наименование

pillow

pip
Затронутые версииВерсия исправления

< 3.1.1

3.1.1

EPSS

Процентиль: 79%
0.01278
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 10 лет назад

Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.

redhat
почти 12 лет назад

Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.

CVSS3: 6.5
nvd
почти 10 лет назад

Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.

CVSS3: 6.5
debian
почти 10 лет назад

Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pil ...

EPSS

Процентиль: 79%
0.01278
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-119