ZeroHour

CVE-2019-16865

CVSS 3.1
7.5 high
EPSS
3%p87
Published
()
Modified
Description

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

Vendors
pythonfedoraproject
Products
pillow, fedora
Weakness
CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.