CVE-2019-19911 PUBLISHED

There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.

EPSS 0.97% · 76.4th percentile

Risk Scores

EPSS Score
0.97%
76.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSpillow0, 5.1.0-1, 5.0.0-1
Ubuntu:16.04:LTSpillow0, 2.9.0-1, 3.0.0-1
Ubuntu:Pro:14.04:LTSpillow0, 2.2.1-2ubuntu1, 2.2.1-1ubuntu2

Timeline

References

Open in Interactive Console →