Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j7mj-748x-7p78

Опубликовано: 22 окт. 2019
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

DOS attack in Pillow when processing specially crafted image files

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

Пакеты

Наименование

pillow

pip
Затронутые версииВерсия исправления

< 6.2.0

6.2.0

EPSS

Процентиль: 90%
0.05198
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

CVSS3: 7.5
redhat
больше 6 лет назад

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

CVSS3: 7.5
nvd
больше 6 лет назад

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

CVSS3: 7.5
debian
больше 6 лет назад

An issue was discovered in Pillow before 6.2.0. When reading specially ...

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость библиотеки для работы с изображениями Pillow, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 90%
0.05198
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-770