Количество 8
Количество 8
CVE-2026-55379
Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.
CVE-2026-55379
Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.
CVE-2026-55379
Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.
CVE-2026-55379
Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.p ...
SUSE-SU-2026:2875-1
Security update for python-Pillow
RLSA-2026:39127
Important: python-pillow security update
ELSA-2026-39127
ELSA-2026-39127: python-pillow security update (IMPORTANT)
openSUSE-SU-2026:21296-1
Security update for python-Pillow
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55379 Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-55379 Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-55379 Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-55379 Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.p ... | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
SUSE-SU-2026:2875-1 Security update for python-Pillow | 2 месяца назад | |||
RLSA-2026:39127 Important: python-pillow security update | 2 месяца назад | |||
ELSA-2026-39127 ELSA-2026-39127: python-pillow security update (IMPORTANT) | 2 месяца назад | |||
openSUSE-SU-2026:21296-1 Security update for python-Pillow | 2 месяца назад |
Уязвимостей на страницу