Lucene search

K
redosRedosROS-20240411-05
HistoryApr 11, 2024 - 12:00 a.m.

ROS-20240411-05

2024-04-1100:00:00
redos.red-soft.ru
14
pillow
imagemath
eval
vulnerability
code generation
arbitrary code execution
unix
remote exploitation

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

Low

EPSS

0.001

Percentile

43.7%

The vulnerability of the eval() function of the ImageMath module of the Pillow image manipulation library is related to
incorrect control of code generation when processing the environment parameter. Exploitation of the vulnerability could
allow an attacker acting remotely to execute arbitrary code

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64python3-pillow< 9.4.0-3UNKNOWN

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

Low

EPSS

0.001

Percentile

43.7%