Description
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2057-1 | pillow security update |
Debian DSA |
DSA-4631-1 | pillow security update |
EUVD |
EUVD-2020-0128 | There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer. |
Github GHSA |
GHSA-5gm3-px64-rw72 | Uncontrolled Resource Consumption in Pillow |
Ubuntu USN |
USN-4272-1 | Pillow vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:32:10.085Z
Reserved: 2019-12-19T00:00:00.000Z
Link: CVE-2019-19911
No data.
Status : Modified
Published: 2020-01-05T22:15:11.300
Modified: 2024-11-21T04:35:38.717
Link: CVE-2019-19911
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN