An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-4631-1 pillow security update
EUVD EUVD EUVD-2019-0102 An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
Github GHSA Github GHSA GHSA-j7mj-748x-7p78 DOS attack in Pillow when processing specially crafted image files
Ubuntu USN Ubuntu USN USN-4272-1 Pillow vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T01:24:48.558Z

Reserved: 2019-09-24T00:00:00

Link: CVE-2019-16865

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-10-04T22:15:11.190

Modified: 2024-11-21T04:31:13.893

Link: CVE-2019-16865

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-10-04T00:00:00Z

Links: CVE-2019-16865 - Bugzilla

cve-icon OpenCVE Enrichment

No data.