QID 981640

QID 981640: Python (pip) Security Update for pillow (GHSA-j7mj-748x-7p78)

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-j7mj-748x-7p78 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981640

    Software Advisories
    Advisory ID Software Component Link
    GHSA-j7mj-748x-7p78 pillow URL Logo github.com/advisories/GHSA-j7mj-748x-7p78