[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2020-1412 --- python-pillow

ID: oval:org.secpod.oval:def:1700323Date: (C)2020-04-28   (M)2023-12-20
Class: PATCHFamily: unix




A flaw was discovered in the way the python-pillow may allocate a large amount of memory or require a long time while processing specially crafted image files, possibly causing a denial of service. Applications that use the library to process untrusted files may be vulnerable to this flaw. A flaw was discovered in python-pillow where it does not properly restrict operations within the bounds of a memory buffer when decoding PCX images. An application that uses python-pillow to decode untrusted images may be vulnerable to this flaw, which can allow an attacker to crash the application or potentially execute code on the system

Platform:
Amazon Linux 2
Product:
python-pillow
Reference:
ALAS2-2020-1412
CVE-2020-5312
CVE-2019-16865
CVE    2
CVE-2020-5312
CVE-2019-16865
CPE    2
cpe:/a:python:python-pillow
cpe:/o:amazon:linux:2

© SecPod Technologies