5
CVSSv2

CVE-2019-16865

Published: 04/10/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in Pillow prior to 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

python pillow

fedoraproject fedora 30

fedoraproject fedora 31

Vendor Advisories

Several security issues were fixed in Pillow ...
Multiple security issues were discovered in Pillow, a Python imaging library, which could result in denial of service and potentially the execution of arbitrary code if malformed PCX, FLI, SGI or TIFF images are processed For the oldstable distribution (stretch), these problems have been fixed in version 400-4+deb9u1 For the stable distribution ...
Synopsis Important: python-pillow security update Type/Severity Security Advisory: Important Topic An update for python-pillow is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) ...
Synopsis Important: python-pillow security update Type/Severity Security Advisory: Important Topic An update for python-pillow is now available for Red Hat Enterprise Linux 80 Update Services for SAP SolutionsRed Hat Product Security has rated this update as having a security impact of Important A Common ...
Synopsis Important: python-pillow security update Type/Severity Security Advisory: Important Topic An update for python-pillow is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) ...
Synopsis Moderate: OpenShift Container Platform 4138 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat OpenShift Container Platform 41Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scorin ...
Synopsis Moderate: OpenShift Container Platform 435 security update Type/Severity Security Advisory: Moderate Topic An update for openshift-enterprise-apb-base-container, openshift-enterprise-mariadb-apb, openshift-enterprise-mysql-apb, and openshift-enterprise-postgresql-apb is now available for Red Hat ...
Synopsis Moderate: OpenShift Container Platform 435 openshift-enterprise-ansible-operator-container security update Type/Severity Security Advisory: Moderate Topic An update for openshift-enterprise-ansible-operator-container is now available for Red Hat OpenShift Container Platform 43Red Hat Product Se ...
A flaw was discovered in the way the python-pillow may allocate a large amount of memory or require a long time while processing specially crafted image files, possibly causing a denial of service Applications that use the library to process untrusted files may be vulnerable to this flaw (CVE-2019-16865) A flaw was discovered in python-pillow whe ...