PT-2016-5191 · Python+1 · Pillow+2

Publicado

2016-02-28

·

Atualizado

2020-05-06

·

CVE-2016-2533

CVSS v4.0

7.1

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Pillow versions prior to 3.1.1 Python Imaging Library (PIL) version 1.1.7 and earlier
Description The issue is related to a buffer overflow in the ImagingPcdDecode function, which can be triggered by a crafted PhotoCD file, allowing remote attackers to cause a denial of service (crash).
Recommendations For Pillow versions prior to 3.1.1, update to version 3.1.1 or later to resolve the issue. For Python Imaging Library (PIL) version 1.1.7 and earlier, update to a version later than 1.1.7 to resolve the issue. As a temporary workaround, consider disabling the use of the ImagingPcdDecode function in PcdDecode.c until a patch is available.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-2533
DLA-422-1
DSA-3499-1
GHSA-3C5C-7235-994J
PYSEC-2016-19
SUSE-SU-2019:2334-1
SUSE-SU-2020:1194-1
USN-3080-1
USN-3090-1

Produtos afetados

Pillow
Python Imaging Library
Ubuntu