Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9189

Опубликовано: 03 окт. 2016
Источник: redhat
CVSS3: 6.5
CVSS2: 4.3

Описание

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

A memory disclosure vulnerability was found in python-pillow. Functions in map.c failed to check for image overflow and check that an offset parameter was within bounds, allowing a crafted image to cause a crash or disclosure of memory.

Отчет

Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5python-imagingWill not fix
Red Hat Enterprise Linux 6python-imagingWill not fix
Red Hat Enterprise Linux 7python-pillowWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1382000python-pillow: Integer overflows leading to memory disclosure in PyImaging_MapBuffer (Map.c)

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 9 лет назад

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

CVSS3: 5.5
nvd
больше 9 лет назад

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

CVSS3: 5.5
debian
больше 9 лет назад

Pillow before 3.3.2 allows context-dependent attackers to obtain sensi ...

CVSS3: 5.5
github
больше 7 лет назад

Pillow Integer overflow in Map.c

6.5 Medium

CVSS3

4.3 Medium

CVSS2