Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-48379

Опубликовано: 01 июл. 2025
Источник: nvd
CVSS3: 7.1
CVSS3: 5.5
EPSS Низкий

Описание

Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checking for available space. This only affects users who save untrusted data as a compressed DDS image. This issue has been patched in version 11.3.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:python:pillow:11.2.1:*:*:*:*:*:*:*

EPSS

Процентиль: 3%
0.00017
Низкий

7.1 High

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 7.1
ubuntu
6 месяцев назад

Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checking for available space. This only affects users who save untrusted data as a compressed DDS image. This issue has been patched in version 11.3.0.

CVSS3: 7.1
redhat
6 месяцев назад

Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checking for available space. This only affects users who save untrusted data as a compressed DDS image. This issue has been patched in version 11.3.0.

CVSS3: 7.1
debian
6 месяцев назад

Pillow is a Python imaging library. In versions 11.2.0 to before 11.3. ...

CVSS3: 7.1
github
6 месяцев назад

Pillow vulnerability can cause write buffer overflow on BCn encoding

EPSS

Процентиль: 3%
0.00017
Низкий

7.1 High

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-122