Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pillow 安全漏洞
Vulnerability Description
Pillow是美国软件开发者Alex Clark所研发的一个对PIL(Python图像处理库)一些BUG修正后的编译版。 Pillow 3.3.2之前的版本中存在安全漏洞。上下文相关的攻击者可通过使用‘crafted image file’方法利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A