Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v9pc-9mvp-x87g

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 5.5

Описание

Pillow Buffer overflow in Jpeg2KEncode.c

Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.

Пакеты

Наименование

pillow

pip
Затронутые версииВерсия исправления

>= 2.5.0, < 3.1.2

3.1.2

EPSS

Процентиль: 84%
0.02583
Низкий

7.1 High

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 9 лет назад

Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.

redhat
больше 10 лет назад

Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.

CVSS3: 5.5
nvd
больше 9 лет назад

Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.

CVSS3: 5.5
debian
больше 9 лет назад

Heap-based buffer overflow in the j2k_encode_entry function in Pillow ...

EPSS

Процентиль: 84%
0.02583
Низкий

7.1 High

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-119