In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade pillow
to version 11.3.0 or higher.
Affected versions of this package are vulnerable to Heap-based Buffer Overflow via the ImagingBcnEncode
function. An attacker can cause memory corruption or potentially execute arbitrary code by saving a specially crafted, large DDS image file as compressed data.
Note: This is only exploitable if untrusted data is saved as a compressed DDS image.