Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rwr3-c2q8-gm56

Опубликовано: 24 июл. 2018
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.5

Описание

Pillow Integer overflow in Map.c

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

Пакеты

Наименование

pillow

pip
Затронутые версииВерсия исправления

< 3.3.2

3.3.2

EPSS

Процентиль: 57%
0.00358
Низкий

6.9 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 9 лет назад

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

CVSS3: 6.5
redhat
больше 9 лет назад

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

CVSS3: 5.5
nvd
больше 9 лет назад

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

CVSS3: 5.5
debian
больше 9 лет назад

Pillow before 3.3.2 allows context-dependent attackers to obtain sensi ...

EPSS

Процентиль: 57%
0.00358
Низкий

6.9 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-190