Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-5312

Опубликовано: 03 янв. 2020
Источник: redhat
CVSS3: 9.8

Описание

libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.

A flaw was discovered in python-pillow does where it does not properly restrict operations within the bounds of a memory buffer when decoding PCX images. An application that uses python-pillow to decode untrusted images may be vulnerable to this flaw, which can allow an attacker to crash the application or potentially execute code on the system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5python-imagingOut of support scope
Red Hat Enterprise Linux 6python-imagingFixedRHSA-2020:089818.03.2020
Red Hat Enterprise Linux 7python-pillowFixedRHSA-2020:057824.02.2020
Red Hat Enterprise Linux 8python-pillowFixedRHSA-2020:058024.02.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutionspython-pillowFixedRHSA-2020:056620.02.2020
Red Hat Quay 3quay/clair-rhel8FixedRHSA-2021:042004.02.2021
Red Hat Quay 3quay/quay-bridge-operator-bundleFixedRHSA-2021:042004.02.2021
Red Hat Quay 3quay/quay-bridge-operator-rhel8FixedRHSA-2021:042004.02.2021
Red Hat Quay 3quay/quay-builder-qemu-rhcos-rhel8FixedRHSA-2021:042004.02.2021
Red Hat Quay 3quay/quay-builder-rhel8FixedRHSA-2021:042004.02.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1789533python-pillow: improperly restricted operations on memory buffer in libImaging/PcxDecode.c

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 6 лет назад

libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.

CVSS3: 9.8
nvd
около 6 лет назад

libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.

CVSS3: 9.8
debian
около 6 лет назад

libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer ...

CVSS3: 9.8
github
больше 4 лет назад

PCX P mode buffer overflow in Pillow

oracle-oval
почти 6 лет назад

ELSA-2020-0898: python-imaging security update (IMPORTANT)

9.8 Critical

CVSS3