Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-16865

Опубликовано: 04 окт. 2019
Источник: redhat
CVSS3: 7.5

Описание

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

A flaw was discovered in the way the python-pillow may allocate a large amount of memory or require a long time while processing specially crafted image files, possibly causing a denial of service. Applications that use the library to process untrusted files may be vulnerable to this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5python-imagingOut of support scope
Red Hat Enterprise Linux 6python-imagingOut of support scope
Red Hat Quay 3quayAffected
Red Hat Enterprise Linux 7python-pillowFixedRHSA-2020:057824.02.2020
Red Hat Enterprise Linux 8python-pillowFixedRHSA-2020:058024.02.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutionspython-pillowFixedRHSA-2020:056620.02.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=1774066python-pillow: reading specially crafted image files leads to allocation of large amounts of memory and denial of service

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

CVSS3: 7.5
nvd
больше 6 лет назад

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

CVSS3: 7.5
debian
больше 6 лет назад

An issue was discovered in Pillow before 6.2.0. When reading specially ...

CVSS3: 7.5
github
больше 6 лет назад

DOS attack in Pillow when processing specially crafted image files

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость библиотеки для работы с изображениями Pillow, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3