Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9601

Опубликовано: 31 дек. 2014
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5python-imagingWill not fix
Red Hat Enterprise Linux 6python-imagingWill not fix
Red Hat Enterprise Linux 7python-pillowWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=1179354python-pillow: potential denial-of-service during PNG decompression

EPSS

Процентиль: 79%
0.01207
Низкий

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.

nvd
около 11 лет назад

Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.

debian
около 11 лет назад

Pillow before 2.7.0 allows remote attackers to cause a denial of servi ...

CVSS3: 7.5
github
больше 3 лет назад

Pillow denial of service via PNG bomb

EPSS

Процентиль: 79%
0.01207
Низкий

2.6 Low

CVSS2