Back

HIGH

python-pillow: reading specially crafted image files leads to allocation of large amounts of memory and denial of service

Published Oct 4, 2019

Description

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 4, 2019
Updated Aug 5, 2024
Reserved Sep 24, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 4, 2019
GHSA-J7MJ-748X-7P78