USN-4697-1: Pillow vulnerabilities
It was discovered that Pillow incorrectly handled certain PCX image files. If a user or automated system were tricked into opening a specially-crafted PCX file, a remote attacker could possibly cause Pillow to crash, resulting in a denial of service. (CVE-2020-35653) It was discovered that Pillow incorrectly handled certain Tiff image files. If a user or automated system were tricked into opening a specially-crafted Tiff file, a remote attacker could cause Pillow to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2020-35654) It was discovered that Pillow incorrectly handled certain SGI image files. If a user or automated system were tricked into opening a specially-crafted SGI file, a remote attacker could possibly cause Pillow to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 20.10. (CVE-2020-35655)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is USN-4697-1.
What is the severity of USN-4697-1?
The severity of USN-4697-1 is not mentioned in the advisory.
What software is affected by USN-4697-1?
The software affected by USN-4697-1 includes python3-pil and python-pil versions 7.2.0-1ubuntu0.1 and earlier, python3-pil version 7.0.0-4ubuntu0.2 and earlier, python-pil version 5.1.0-1ubuntu0.4 and earlier.
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by tricking a user or automated system into opening a specially-crafted PCX file, which could cause Pillow to crash and result in a denial of service.
What is the remedy for this vulnerability?
The remedy for this vulnerability is to upgrade python3-pil and python-pil to version 7.2.0-1ubuntu0.1, python3-pil to version 7.0.0-4ubuntu0.2, and python-pil to version 5.1.0-1ubuntu0.4 or later.