Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-28677

Опубликовано: 02 июн. 2021
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.

РелизСтатусПримечание
bionic

released

5.1.0-1ubuntu0.6
devel

released

8.1.2+dfsg-0.1ubuntu1
esm-infra-legacy/trusty

released

2.3.0-1ubuntu3.4+esm5
esm-infra/bionic

released

5.1.0-1ubuntu0.6
esm-infra/focal

released

7.0.0-4ubuntu0.4
esm-infra/xenial

released

3.1.2-0ubuntu1.6+esm3
focal

released

7.0.0-4ubuntu0.4
groovy

released

7.2.0-1ubuntu0.3
hirsute

released

8.1.2-1ubuntu0.1
impish

released

8.1.2+dfsg-0.1ubuntu1

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps/focal

needs-triage

esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needs-triage
groovy

ignored

end of life
hirsute

DNE

impish

DNE

jammy

DNE

kinetic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

impish

DNE

jammy

DNE

kinetic

DNE

Показывать по

EPSS

Процентиль: 50%
0.00263
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
около 5 лет назад

An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.

CVSS3: 7.5
nvd
почти 5 лет назад

An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.

CVSS3: 7.5
debian
почти 5 лет назад

An issue was discovered in Pillow before 8.2.0. For EPS data, the read ...

CVSS3: 7.5
github
почти 5 лет назад

Uncontrolled Resource Consumption in Pillow

CVSS3: 7.5
fstec
около 5 лет назад

Уязвимость реализации readline компонента EPSImageFile библиотеки для работы с изображениями Pillow, связанная с недостаточной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 50%
0.00263
Низкий

5 Medium

CVSS2

7.5 High

CVSS3