Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rwr3-c2q8-gm56

Опубликовано: 24 июл. 2018
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.5

Описание

Pillow Integer overflow in Map.c

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

Пакеты

Наименование

pillow

pip
Затронутые версииВерсия исправления

< 3.3.2

3.3.2

EPSS

Процентиль: 78%
0.01877
Низкий

6.9 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 10 лет назад

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

CVSS3: 6.5
redhat
почти 10 лет назад

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

CVSS3: 5.5
nvd
почти 10 лет назад

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

CVSS3: 5.5
debian
почти 10 лет назад

Pillow before 3.3.2 allows context-dependent attackers to obtain sensi ...

EPSS

Процентиль: 78%
0.01877
Низкий

6.9 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-190