漏洞信息详情
Pillow 缓冲区错误漏洞
漏洞简介
Pillow是一款基于Python的图像处理库。
Pillow 中存在缓冲区错误漏洞,该漏洞源于产品的convert .c未能验证参数的安全性,攻击者可通过该漏洞引发缓冲区溢出。以下产品及版本受到影响:Pillow 8.2.0 之前版本、PIL 1.1.7 之前版本。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://pillow.readthedocs.io/en/stable/releasenotes/8.3.0.html#buffer-overflow
参考网址
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2021/07/msg00018.html
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/VUGBBT63VL7G4JNOEIPDJIOC34ZFBKNJ/
来源:MISC
链接:https://pillow.readthedocs.io/en/stable/releasenotes/index.html
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/7V6LCG525ARIX6LX5QRYNAWVDD2MD2SV/
来源:MISC
链接:https://pillow.readthedocs.io/en/stable/releasenotes/8.3.0.html#buffer-overflow
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Pillow-buffer-overflow-via-Convert-c-35973
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164871/Red-Hat-Security-Advisory-2021-4149-03.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3472
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2665
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2620
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2498
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3919
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2021-34552
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3811
受影响实体
暂无
补丁
- Pillow 缓冲区错误漏洞的修复措施<!--2021-7-13-->
还没有评论,来说两句吧...