First published: Fri Jan 16 2015(Updated: )
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/pillow | <2.7.0 | 2.7.0 |
Python Imaging Library (Pillow) | <=2.6.2 | |
Oracle Solaris and Zettabyte File System (ZFS) | =11.2 | |
Fedora | =21 | |
SUSE Linux | =13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9601 has been classified as a high-severity vulnerability due to its potential to cause denial of service.
To fix CVE-2014-9601, upgrade Pillow to version 2.7.0 or later.
The impact of CVE-2014-9601 is that it allows remote attackers to trigger a denial of service by exploiting compressed text chunks in PNG images.
Pillow versions prior to 2.7.0 are affected by CVE-2014-9601.
Yes, CVE-2014-9601 can be exploited remotely through specially crafted PNG images.