An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-3768-1 | pillow security update |
![]() |
DSA-5704-1 | pillow security update |
![]() |
GHSA-8ghj-p4vj-mr35 | Pillow Denial of Service vulnerability |
![]() |
USN-6618-1 | Pillow vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T19:59:51.982Z
Reserved: 2023-09-28T00:00:00
Link: CVE-2023-44271

No data.

Status : Modified
Published: 2023-11-03T05:15:30.137
Modified: 2024-11-21T08:25:33.610
Link: CVE-2023-44271


No data.