Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pillow 缓冲区错误漏洞
Vulnerability Description
Pillow是美国软件开发者Alex Clark所研发的一个对PIL(Python图像处理库)一些BUG修正后的编译版。 Pillow 2.5.0版本至3.1.1版本中‘j2k_encode_entry’函数存在基于堆的缓冲区溢出漏洞。远程攻击者可借助特制的Jpeg2000文件利用该漏洞造成拒绝服务(内存损坏)。
CVSS Information
N/A
Vulnerability Type
N/A