Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Pillow Vulnerable to Write Buffer Overflow on BCn encoding
Vulnerability Description
Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checking for available space. This only affects users who save untrusted data as a compressed DDS image. This issue has been patched in version 11.3.0.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Vulnerability Type
堆缓冲区溢出
Vulnerability Title
Pillow 安全漏洞
Vulnerability Description
Pillow是Pillow开源的一款基于Python的图像处理库。 Pillow 11.2.0至11.3.0之前版本存在安全漏洞,该漏洞源于DDS格式图像写入时存在堆缓冲区溢出,可能导致执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A