Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5h2q-4hrp-v9rr

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Django vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer

The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

< 1.3.2

1.3.2

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.4, < 1.4.1

1.4.1

EPSS

Процентиль: 78%
0.0119
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-119

Связанные уязвимости

ubuntu
почти 13 лет назад

The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image.

nvd
почти 13 лет назад

The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image.

debian
почти 13 лет назад

The get_image_dimensions function in the image-handling functionality ...

EPSS

Процентиль: 78%
0.0119
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-119