FlawAtlas
Search the atlas
CVE-2014-3589 High

CVE-2014-3589

PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.

Exploit probability 3.3%
Published August 25, 2014
Required by Not available
Last source change June 10, 2026

02 / AFFECTED SOFTWARE

Affected packages

PyPI pillow

25 explicit affected versions

PyPI pillow

25 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2014-3589

PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.

View original source
Open Source Vulnerabilities PYSEC-2014-10

PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.

View original source
Open Source Vulnerabilities GHSA-cfmr-38g9-f2h7

`PIL/IcnsImagePlugin.py` in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.

View original source

05 / REFERENCES

Further evidence