Heap-based buffer overflow in the j2kencodeentry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "3.0.0-rc1"
}
],
"cpe": "cpe:2.3:a:python:pillow:3.0.0:rc1:*:*:*:*:*:*"
}
]
}{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.5.0"
},
{
"last_affected": "2.5.1"
},
{
"last_affected": "2.5.2"
},
{
"last_affected": "2.5.3"
},
{
"last_affected": "2.6.0"
},
{
"last_affected": "2.6.0-rc1"
},
{
"last_affected": "2.6.1"
},
{
"last_affected": "2.6.2"
},
{
"last_affected": "2.7.0"
},
{
"last_affected": "2.8.0"
},
{
"last_affected": "2.8.1"
},
{
"last_affected": "2.8.2"
},
{
"last_affected": "2.9.0"
},
{
"last_affected": "2.9.0-dev0"
},
{
"last_affected": "2.9.0-dev1"
},
{
"last_affected": "2.9.0-dev2"
},
{
"last_affected": "3.0.0"
},
{
"last_affected": "3.1.0"
}
],
"cpe": [
"cpe:2.3:a:python:pillow:2.5.0:*:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:2.5.1:*:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:2.5.2:*:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:2.5.3:*:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:2.6.0:*:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:2.6.0:rc1:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:2.6.1:*:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:2.6.2:*:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:2.7.0:*:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:2.8.0:*:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:2.8.1:*:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:2.8.2:*:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:2.9.0:*:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:2.9.0:dev0:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:2.9.0:dev1:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:2.9.0:dev2:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:3.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:python:pillow:3.1.0:*:*:*:*:*:*:*"
]
}