Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
Vulnerability Description
Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
整数溢出或超界折返
Vulnerability Title
python-pillow Pillow 数字错误漏洞
Vulnerability Description
python-pillow Pillow是python-pillow的图像处理库。 python-pillow Pillow 12.3.0之前版本存在安全漏洞,该漏洞源于在Image.paste()、Image.crop()或Image.alpha_composite()函数中,当给定接近32位有符号整数边界的坐标时,会触发原生堆越界写入,导致容易受到拒绝服务攻击。
CVSS Information
N/A
Vulnerability Type
N/A