CVE-2019-16865
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
02 / AFFECTED SOFTWARE
Affected packages
34 explicit affected versions
66 explicit affected versions
66 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2020:0566
- https://access.redhat.com/errata/RHSA-2020:0578
- https://access.redhat.com/errata/RHSA-2020:0580
- https://access.redhat.com/errata/RHSA-2020:0681
- https://access.redhat.com/errata/RHSA-2020:0683
- https://access.redhat.com/errata/RHSA-2020:0694
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EMJBUZQGQ2Q7HXYCQVRLU7OXNC7CAWWU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LYDXD7EE4YAEVSTNIFZKNVPRVJX5ZOG3/
- https://pillow.readthedocs.io/en/latest/releasenotes/6.2.0.html
- https://usn.ubuntu.com/4272-1/
- https://www.debian.org/security/2020/dsa-4631
- https://github.com/advisories/GHSA-j7mj-748x-7p78
- https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2019-110.yaml
- https://github.com/python-pillow/Pillow
- https://github.com/python-pillow/Pillow/commit/ab52630d0644e42a75eb88b78b9a9d7438a6fbeb
- https://github.com/python-pillow/Pillow/issues/4123
- https://lists.fedoraproject.org/archives/list/[email protected]/message/EMJBUZQGQ2Q7HXYCQVRLU7OXNC7CAWWU
- https://lists.fedoraproject.org/archives/list/[email protected]/message/LYDXD7EE4YAEVSTNIFZKNVPRVJX5ZOG3
- https://nvd.nist.gov/vuln/detail/CVE-2019-16865
- https://ubuntu.com/security/notices/USN-4272-1
- https://usn.ubuntu.com/4272-1
- https://lists.fedoraproject.org/archives/list/[email protected]/message/EMJBUZQGQ2Q7HXYCQVRLU7OXNC7CAWWU/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/LYDXD7EE4YAEVSTNIFZKNVPRVJX5ZOG3/