CVE-2014-3598: High severity opensuse vulnerability
Published May 1, 2015
·Updated
The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image.
Affected Software
3 affected componentsFixes available
pip/pillow<2.5.3
2.5.3
openSUSE openSUSE=13.2
Python Pillow<=2.5.2
Event History
May 1, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·02:05 AM
Frequently Asked Questions
1
What is the severity of CVE-2014-3598?
CVE-2014-3598 is classified as a denial of service vulnerability that can impact application availability.
2
How do I fix CVE-2014-3598?
To fix CVE-2014-3598, upgrade to Pillow version 2.5.3 or later.
3
Which Pillow versions are affected by CVE-2014-3598?
Pillow versions prior to 2.5.3, specifically those up to and including 2.5.2, are affected by CVE-2014-3598.
4
Can CVE-2014-3598 be exploited remotely?
Yes, CVE-2014-3598 can be exploited remotely by sending crafted image files to the vulnerable application.
5
What platforms are affected by CVE-2014-3598?
CVE-2014-3598 affects any software using Pillow versions below 2.5.3, particularly on platforms like openSUSE 13.2.