CVE-2019-16865

EUVD-2019-0102
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
Affected Products (NVD)
VendorProductVersion
pythonpillow
𝑥
< 6.2.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pillow
bookworm
9.4.0-1.1+deb12u1
fixed
bookworm (security)
9.4.0-1.1+deb12u1
fixed
bullseye
8.1.2+dfsg-0.3+deb11u2
fixed
bullseye (security)
8.1.2+dfsg-0.3+deb11u2
fixed
jessie
ignored
sid
10.4.0-1
fixed
stretch
ignored
trixie
10.4.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pillow
bionic
Fixed 5.1.0-1ubuntu0.2
released
disco
ignored
eoan
Fixed 6.1.0-1ubuntu0.2
released
trusty
Fixed 2.3.0-1ubuntu3.4+esm1
released
xenial
Fixed 3.1.2-0ubuntu1.3
released