Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wjx4-4jcj-g98j

Опубликовано: 04 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 5.5

Описание

Pillow has an integer overflow when processing fonts

If a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This has been fixed.

Пакеты

Наименование

pillow

pip
Затронутые версииВерсия исправления

< 12.2.0

12.2.0

EPSS

Процентиль: 2%
0.00114
Низкий

5.1 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 месяца назад

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.

CVSS3: 6.2
redhat
3 месяца назад

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.

CVSS3: 5.5
nvd
3 месяца назад

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.

CVSS3: 5.5
debian
3 месяца назад

Pillow is a Python imaging library. Prior to version 12.2.0, if a font ...

suse-cvrf
2 месяца назад

Security update for python-Pillow

EPSS

Процентиль: 2%
0.00114
Низкий

5.1 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-190