Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-95q3-8gr9-gm8w

Опубликовано: 18 мар. 2021
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Pillow Denial of Service by Uncontrolled Resource Consumption

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.

Пакеты

Наименование

pillow

pip
Затронутые версииВерсия исправления

< 8.1.2

8.1.2

EPSS

Процентиль: 61%
0.00419
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-20
CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.

CVSS3: 7.5
redhat
почти 5 лет назад

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.

CVSS3: 7.5
nvd
почти 5 лет назад

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.

CVSS3: 7.5
debian
почти 5 лет назад

Pillow before 8.1.2 allows attackers to cause a denial of service (mem ...

suse-cvrf
больше 1 года назад

Security update for python-Pillow

EPSS

Процентиль: 61%
0.00419
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-20
CWE-400