CVE-2019-16865
Summary
| CVE | CVE-2019-16865 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-04 22:15:00 UTC |
| Updated | 2023-11-07 03:06:00 UTC |
| Description | An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image. |
Risk And Classification
Problem Types: CWE-770
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 30 | All | All | All |
| Operating System | Fedoraproject | Fedora | 31 | All | All | All |
| Operating System | Fedoraproject | Fedora | 30 | All | All | All |
| Operating System | Fedoraproject | Fedora | 31 | All | All | All |
| Application | Python | Pillow | All | All | All | All |
| Application | Python | Pillow | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| [SECURITY] Fedora 30 Update: python-pillow-5.4.1-3.fc30 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| 6.2.0 — Pillow (PIL Fork) 7.0.0.dev0 documentation | MISC | pillow.readthedocs.io | Release Notes, Vendor Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| [SECURITY] Fedora 30 Update: python-pillow-5.4.1-3.fc30 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| Debian -- Security Information -- DSA-4631-1 pillow | DEBIAN | www.debian.org | |
| [SECURITY] Fedora 31 Update: python-pillow-6.1.0-4.fc31 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| USN-4272-1: Pillow vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | |
| [SECURITY] Fedora 31 Update: python-pillow-6.1.0-4.fc31 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296076 Oracle Solaris 11.4 Support Repository Update (SRU) 19.3.0 Missing (CPUJAN2020)
- 377249 Alibaba Cloud Linux Security Update for python-pillow (ALINUX2-SA-2020:0024)
- 377325 Alibaba Cloud Linux Security Update for python-pillow (ALINUX3-SA-2022:0012)
- 981640 Python (pip) Security Update for pillow (GHSA-j7mj-748x-7p78)