DOS attack in Pillow when processing specially crafted image files
High severity
GitHub Reviewed
Published
Oct 22, 2019
to the GitHub Advisory Database
•
Updated Oct 9, 2024
Description
Reviewed
Oct 17, 2019
Published to the GitHub Advisory Database
Oct 22, 2019
Last updated
Oct 9, 2024
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
References