Back

HIGH

python-pillow: uncontrolled resource consumption in FpxImagePlugin.py

Published Jan 5, 2020

Description

There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of python-pillow as shipped with Red Hat Enterprise Linux 7, and 8 as they did not include python-olefile, which is necessary to use the FPX image plugin.

References (14)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Jan 5, 2020
Updated Aug 5, 2024
Reserved Dec 19, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jan 3, 2020
Bugzilla 1789540

ENISA EUVD

Assigner mitre
Published Jan 5, 2020
Updated Aug 5, 2024