Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-19911

Опубликовано: 03 янв. 2020
Источник: redhat
CVSS3: 7.5

Описание

There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.

A denial of service vulnerability was found in Pillow in versions before 6.2.2, where the FpxImagePlugin.py file calls the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows systems running 32-bit Python, this flaw results in an OverflowError or MemoryError due to the 2 GB limit. On Linux systems running 64-bit Python, this flaw results in the termination of the process by the out-of-memory (OOM) killer. The highest threat from this vulnerability is to system availability.

Отчет

This issue did not affect the versions of python-pillow as shipped with Red Hat Enterprise Linux 7, and 8 as they did not include python-olefile, which is necessary to use the FPX image plugin.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5python-imagingOut of support scope
Red Hat Enterprise Linux 6python-imagingOut of support scope
Red Hat Enterprise Linux 7python-pillowNot affected
Red Hat Enterprise Linux 8python-pillowNot affected
Red Hat Quay 3quay/clair-rhel8FixedRHSA-2021:042004.02.2021
Red Hat Quay 3quay/quay-bridge-operator-bundleFixedRHSA-2021:042004.02.2021
Red Hat Quay 3quay/quay-bridge-operator-rhel8FixedRHSA-2021:042004.02.2021
Red Hat Quay 3quay/quay-builder-qemu-rhcos-rhel8FixedRHSA-2021:042004.02.2021
Red Hat Quay 3quay/quay-builder-rhel8FixedRHSA-2021:042004.02.2021
Red Hat Quay 3quay/quay-container-security-operator-bundleFixedRHSA-2021:042004.02.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1789540python-pillow: uncontrolled resource consumption in FpxImagePlugin.py

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.

CVSS3: 7.5
nvd
около 6 лет назад

There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.

CVSS3: 7.5
debian
около 6 лет назад

There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImage ...

CVSS3: 7.5
github
почти 6 лет назад

Uncontrolled Resource Consumption in Pillow

fstec
около 6 лет назад

Уязвимость функции _open_index из FpxImagePlugin.py библиотеки для работы с изображениями Pillow, связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3