Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-28677

Опубликовано: 02 июн. 2021
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.

РелизСтатусПримечание
bionic

released

5.1.0-1ubuntu0.6
devel

released

8.1.2+dfsg-0.1ubuntu1
esm-infra-legacy/trusty

needs-triage

esm-infra/bionic

released

5.1.0-1ubuntu0.6
esm-infra/focal

released

7.0.0-4ubuntu0.4
esm-infra/xenial

needs-triage

focal

released

7.0.0-4ubuntu0.4
groovy

released

7.2.0-1ubuntu0.3
hirsute

released

8.1.2-1ubuntu0.1
impish

released

8.1.2+dfsg-0.1ubuntu1

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps/focal

needs-triage

esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needs-triage
groovy

ignored

end of life
hirsute

DNE

impish

DNE

jammy

DNE

kinetic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

impish

DNE

jammy

DNE

kinetic

DNE

Показывать по

EPSS

Процентиль: 49%
0.00263
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 5 лет назад

An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.

CVSS3: 7.5
nvd
больше 4 лет назад

An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.

CVSS3: 7.5
debian
больше 4 лет назад

An issue was discovered in Pillow before 8.2.0. For EPS data, the read ...

CVSS3: 7.5
github
больше 4 лет назад

Uncontrolled Resource Consumption in Pillow

CVSS3: 7.5
fstec
почти 5 лет назад

Уязвимость реализации readline компонента EPSImageFile библиотеки для работы с изображениями Pillow, связанная с недостаточной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 49%
0.00263
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Уязвимость CVE-2021-28677