python-pillow: uncontrolled resource consumption in FpxImagePlugin.py
Published Jan 5, 2020
8.7
HIGHCVSS 4.0
EPSS 2.12%
Description
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.
Affected products
No data.
Configuration 2
- 9.0
- 10.0
Configuration 3
- 30
Configuration 4
- 14.04
- 16.04
- 18.04
- 19.10
No data.
Red Hat Quay 3
quay/clair-rhel8:v3.4.0-25
Fixed · RHSA-2021:0420
Red Hat Quay 3
quay/quay-bridge-operator-bundle:v3.4.0-3
Fixed · RHSA-2021:0420
Red Hat Quay 3
quay/quay-bridge-operator-rhel8:v3.4.0-17
Fixed · RHSA-2021:0420
Red Hat Quay 3
quay/quay-builder-qemu-rhcos-rhel8:v3.4.0-17
Fixed · RHSA-2021:0420
Red Hat Quay 3
quay/quay-builder-rhel8:v3.4.0-18
Fixed · RHSA-2021:0420
Red Hat Quay 3
quay/quay-container-security-operator-bundle:v3.4.0-2
Fixed · RHSA-2021:0420
Red Hat Quay 3
quay/quay-container-security-operator-rhel8:v3.4.0-2
Fixed · RHSA-2021:0420
Red Hat Quay 3
quay/quay-openshift-bridge-rhel8-operator:v3.4.0-17
Fixed · RHSA-2021:0420
Red Hat Quay 3
quay/quay-operator-bundle:v3.4.0-89
Fixed · RHSA-2021:0420
Red Hat Quay 3
quay/quay-operator-rhel8:v3.4.0-132
Fixed · RHSA-2021:0420
Red Hat Quay 3
quay/quay-rhel8:v3.4.0-51
Fixed · RHSA-2021:0420
Red Hat Enterprise Linux 5
python-imaging
Out of support scope
Red Hat Enterprise Linux 6
python-imaging
Out of support scope
Red Hat Enterprise Linux 7
python-pillow
Not affected
Red Hat Enterprise Linux 8
python-pillow
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Quay 3 | quay/clair-rhel8:v3.4.0-25 | Fixed | RHSA-2021:0420 |
| Red Hat Quay 3 | quay/quay-bridge-operator-bundle:v3.4.0-3 | Fixed | RHSA-2021:0420 |
| Red Hat Quay 3 | quay/quay-bridge-operator-rhel8:v3.4.0-17 | Fixed | RHSA-2021:0420 |
| Red Hat Quay 3 | quay/quay-builder-qemu-rhcos-rhel8:v3.4.0-17 | Fixed | RHSA-2021:0420 |
| Red Hat Quay 3 | quay/quay-builder-rhel8:v3.4.0-18 | Fixed | RHSA-2021:0420 |
| Red Hat Quay 3 | quay/quay-container-security-operator-bundle:v3.4.0-2 | Fixed | RHSA-2021:0420 |
| Red Hat Quay 3 | quay/quay-container-security-operator-rhel8:v3.4.0-2 | Fixed | RHSA-2021:0420 |
| Red Hat Quay 3 | quay/quay-openshift-bridge-rhel8-operator:v3.4.0-17 | Fixed | RHSA-2021:0420 |
| Red Hat Quay 3 | quay/quay-operator-bundle:v3.4.0-89 | Fixed | RHSA-2021:0420 |
| Red Hat Quay 3 | quay/quay-operator-rhel8:v3.4.0-132 | Fixed | RHSA-2021:0420 |
| Red Hat Quay 3 | quay/quay-rhel8:v3.4.0-51 | Fixed | RHSA-2021:0420 |
| Red Hat Enterprise Linux 5 | python-imaging | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | python-imaging | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | python-pillow | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python-pillow | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of python-pillow as shipped with Red Hat Enterprise Linux 7, and 8 as they did not include python-olefile, which is necessary to use the FPX image plugin.
References (14)
- https://access.redhat.com/security/cve/CVE-2019-19911 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1789540 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0128 Advisory
- https://github.com/advisories/GHSA-5gm3-px64-rw72 Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2020-172.yaml
- https://github.com/python-pillow/Pillow/blob/master/CHANGES.rst#622-2020-01-02
- https://github.com/python-pillow/Pillow/commit/774e53bb132461d8d5ebefec1162e29ec0ebc63d
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3DUMIBUYGJRAVJCTFUWBRLVQKOUTVX5P/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3DUMIBUYGJRAVJCTFUWBRLVQKOUTVX5P
- https://nvd.nist.gov/vuln/detail/CVE-2019-19911
- https://pillow.readthedocs.io/en/stable/releasenotes/6.2.2.html x_refsource_CONFIRMRelease NotesThird Party Advisory
- https://usn.ubuntu.com/4272-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-19911
- https://www.debian.org/security/2020/dsa-4631 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub