CVE-2019-16865: High severity Python Pillow vulnerability
A flaw was discovered in the way the python-pillow may allocate a large amount of memory or require a long time while processing specially crafted image files, possibly causing a denial of service. Applications that use the library to process untrusted files may be vulnerable to this flaw.
Other sources
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 0:2.0.0-20.gitd1c6db8.el7_7 - Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 0:5.1.1-10.el8_1 - Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 0:5.1.1-10.el8_0 - Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 6.2.0 - Upgrade
Upgrade
pip/pillowto a version that resolves this vulnerability.Fixed in 6.2.0 - Upgrade
Upgrade
debian/pillowto a version that resolves this vulnerability.Fixed in 8.1.2+dfsg-0.3+deb11u2Fixed in 8.1.2+dfsg-0.3+deb11u3Fixed in 9.4.0-1.1+deb12u1Fixed in 11.1.0-5+deb13u4Fixed in 11.1.0-5+deb13u3Fixed in 12.2.0-1Fixed in 12.3.0-1 - Upgrade
Upgrade
python-pillowto a version that resolves this vulnerability.Fixed in 6.2.0Patch CVE-2019-16865
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-16865.
What is the severity of CVE-2019-16865?
The severity of CVE-2019-16865 is high (7 out of 10).
What is the affected software?
The affected software is python-pillow.
How does the vulnerability affect the software?
The vulnerability may allow an attacker to allocate a large amount of memory or cause a denial of service by processing specially crafted image files.
How can I fix CVE-2019-16865?
To fix CVE-2019-16865, update to version 6.2.0 of python-pillow.