CVE-2022-24902
tkvideo has a memory issue in playing videos
4.3
MEDIUM
CVSS 3.1
EPSS 0.15%
描述
TkVideoplayer is a simple library to play video files in tkinter. Uncontrolled memory consumption in versions of TKVideoplayer prior to 2.0.0 can theoretically lead to performance degradation. There are no known workarounds. This issue has been patched and users are advised to upgrade to version 2.0.0 or later.
如何修補 CVE-2022-24902
要修補 CVE-2022-24902,請將受影響套件升級到下列已修補版本。
- —升級至 2.0.0 或更新版本
- —升級至 2.0.0 或更新版本
CVE-2022-24902 正在被利用嗎?
低 — EPSS 為 0.1%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2.0.0
- from 0, < 2.0.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |