Количество 8
Количество 8
GHSA-fj7v-r99m-22gq
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
CVE-2026-59198
Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.
CVE-2026-59198
Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.
CVE-2026-59198
Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.
CVE-2026-59198
Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's ...
BDU:2026-09899
Уязвимость функции ImagingTgaRleEncode() компонента TgaRleEncode.c библиотеки для работы с изображениями Pillow, позволяющая нарушителю раскрыть защищаемую информацию
SUSE-SU-2026:3084-1
Security update for python-Pillow
SUSE-SU-2026:3268-1
Security update for python-Pillow
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-fj7v-r99m-22gq Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images | CVSS3: 6.5 | 0% Низкий | 12 дней назад | |
CVE-2026-59198 Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0. | CVSS3: 6.5 | 0% Низкий | 18 дней назад | |
CVE-2026-59198 Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0. | CVSS3: 6.5 | 0% Низкий | 18 дней назад | |
CVE-2026-59198 Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0. | CVSS3: 6.5 | 0% Низкий | 18 дней назад | |
CVE-2026-59198 Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's ... | CVSS3: 6.5 | 0% Низкий | 18 дней назад | |
BDU:2026-09899 Уязвимость функции ImagingTgaRleEncode() компонента TgaRleEncode.c библиотеки для работы с изображениями Pillow, позволяющая нарушителю раскрыть защищаемую информацию | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
SUSE-SU-2026:3084-1 Security update for python-Pillow | 16 дней назад | |||
SUSE-SU-2026:3268-1 Security update for python-Pillow | 5 дней назад |
Уязвимостей на страницу