Pillow和Python Imaging Library 缓冲区溢出漏洞

情报来源:CNNVD

发布时间:2016-02-02

基本信息
  • 漏洞ID:1149242
  • 漏洞类型:缓冲区溢出
  • 发布日期:2016-02-02
  • 更新时间:2017-01-12
  • CVE编号:CVE-2016-2533
  • CNNVD-ID:CNNVD-201604-280
  • 漏洞平台:N/A
  • CVSS评分:4.3
漏洞来源

<a href="https://www.securityfocus.com/bid/82449" target="_blank">https://www.securityfocus.com/bid/82449</a><br/> <a href="http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201604-280" target="_blank">http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201604-280</a><br/>

漏洞详情

PythonImageLibrary(PIL)是瑞士软件开发者FredrikLundh所研发的一个Python图像处理库。Pillow3.1.1之前版本和PIL1.1.7及之前版本的PcdDecode.c文件中的‘ImagingPcdDecode’函数存在缓冲区溢出漏洞。远程攻击者可借助特制的PhotoCD文件利用该漏洞造成拒绝服务(崩溃)。

参考资料


来源:github.com
链接:https://github.com/python-pillow/Pillow/blob/c3cb690fed5d4bf0c45576759de55d054916c165/CHANGES.rst
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2016/02/22/2
来源:DEBIAN
链接:http://www.debian.org/security/2016/dsa-3499
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2016/02/02/5
来源:github.com
链接:https://github.com/python-pillow/Pillow/pull/1706
来源:github.com
链接:https://github.com/python-pillow/Pillow/commit/5bdf54b5a76b54fb00bd05f2d733e0a4173eefc9#diff-8ff6909c159597e22288ad818938fd6b
来源:github.com
链接:https://github.com/python-pillow/Pillow/commit/ae453aa18b66af54e7ff716f4ccb33adca60afd4#diff-8ff6909c159597e22288ad818938fd6b