CVE-2023-44271: High severity Python Pillow vulnerability
Published Nov 3, 2023
·Updated
An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
Affected Software
8 affected componentsFixes available
ubuntu/pillow<7.0.0-4ubuntu0.8
7.0.0-4ubuntu0.8
ubuntu/pillow<9.0.1-1ubuntu0.2
9.0.1-1ubuntu0.2
ubuntu/pillow<10.0.0-1
10.0.0-1
debian/pillow<=5.4.1-2+deb10u3, <=8.1.2+dfsg-0.3+deb11u1, <=9.4.0-1.1
5.4.1-2+deb10u610.3.0-2
pip/pillow>=0<10.0.0
10.0.0
Python Pillow<10.0.0
Fedoraproject Fedora=38
redhat/Pillow<10.0.0
10.0.0
Remediation
Patch Available
Event History
Nov 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
via GitHub·06:36 AM
Data Sourced
via Red Hat·04:39 PM
DescriptionSeverityAffected Software
Mar 30, 2024
Data Sourced
via Launchpad·06:01 PM
Description