Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile…
高危 CVSS 7.5
摘要
Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/python-pillow/Pillow/commit/13ada41172142f2fd9f0906f615a00ea623a11ca Patch
- https://github.com/python-pillow/Pillow/pull/9704 Exploit
- https://github.com/python-pillow/Pillow/releases/tag/12.3.0 Release Notes
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44j Exploit
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44j Exploit
时间线
- nvd_ingest NVD