漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
Vulnerability Description
Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
Vulnerability Type
跨界内存读
Vulnerability Title
python-pillow Pillow 缓冲区错误漏洞
Vulnerability Description
python-pillow Pillow是python-pillow的图像处理库。 python-pillow Pillow 5.2.0版本至12.3.0之前版本存在缓冲区错误漏洞,该漏洞源于TGA RLE编码器在处理模式1图像的TGA RLE压缩时读取超出已压缩行缓冲区范围,允许相邻进程堆字节复制到生成的TGA文件中。
CVSS Information
N/A
Vulnerability Type
N/A