5
CVSSv2

CVE-2014-3598

Published: 01/05/2015 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The Jpeg2KImagePlugin plugin in Pillow prior to 2.5.3 allows remote malicious users to cause a denial of service via a crafted image.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 13.2

python pillow

Vendor Advisories

Debian Bug report logs - #758772 CVE-2014-3589 Package: src:pillow; Maintainer for src:pillow is Matthias Klose <doko@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 21 Aug 2014 06:45:01 UTC Severity: important Tags: security Fixed in version pillow/253-1 Done: Matthias Klose <doko@deb ...
The Jpeg2KImagePlugin plugin in Pillow before 253 allows remote attackers to cause a denial of service via a crafted image ...