An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-11-03T00:00:00
Updated: 2024-08-02T19:59:51.982Z
Reserved: 2023-09-28T00:00:00
Link: CVE-2023-44271
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-11-03T05:15:30.137
Modified: 2024-03-22T11:15:46.063
Link: CVE-2023-44271
Redhat