QID 198632

Date Published: 2022-01-17

QID 198632: Ubuntu Security Notification for Pillow Vulnerabilities (USN-5227-1)

Pillow incorrectly handled certain image files.
Pillow incorrectly handled certain image files.
Pillow incorrectly handled certain image files.
Pillow incorrectly handled certain image files.
Pillow incorrectly handled certain image files.

If auser or automated system were tricked into opening a specially-craftedfile, a remote attacker could cause pillow to hang, resulting in a denialof service.
If auser or automated system were tricked into opening a specially-craftedfile, a remote attacker could cause pillow to crash, resulting in a denialof service.
If auser or automated system were tricked into opening a specially-craftedfile, a remote attacker could cause pillow to crash, resulting in a denialof service, or possibly execute arbitrary code.
If auser or automated system were tricked into opening a specially-craftedfile, a remote attacker could cause pillow to crash, resulting in a denialof service.
If auser or automated system were tricked into opening a specially-craftedfile, a remote attacker could cause pillow to crash, resulting in a denialof service, or possibly execute arbitrary code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5227-1 for updates and patch information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-5227-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5227-1