VDB
EN

PYSEC-2023-227

상세

An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / pillow
최초 영향 버전: 0 수정 버전: 1fe1bb49c452b0318cad12ea9d97c3bef188e9a7
수정 pip install --upgrade 'pillow>=1fe1bb49c452b0318cad12ea9d97c3bef188e9a7'

참고