Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding …
高危 CVSS 7.5
摘要
Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/python-pillow/Pillow/commit/f7a31ea75e460e108c37126da1f47812f21f6b09 Patch
- https://github.com/python-pillow/Pillow/pull/9718 Issue Tracking
- https://github.com/python-pillow/Pillow/releases/tag/12.3.0 Release Notes
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565 Exploit
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565 Exploit
时间线
- nvd_ingest NVD