CVE-2014-3589
published 2014-08-25CVE-2014-3589: PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.33%
87.4th percentile
PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pillow | < pillow 2.5.3-1 (bookworm) | pillow 2.5.3-1 (bookworm) |
| opensuse | opensuse | — | — |
| python | pillow | <= 2.3.1 | — |
| python | pillow | — | — |
| python | pillow | — | — |
| python | pillow | — | — |
| python | pillow | — | — |
| python | pillow | >= 0 < 2.5.3-1 | 2.5.3-1 |
| python | pillow | >= 0 < 2.5.3-1 | 2.5.3-1 |
| python | pillow | >= 0 < 2.5.3-1 | 2.5.3-1 |
| python | pillow | >= 0 < 2.5.3-1 | 2.5.3-1 |
| python | pillow | >= 0 < 2.3.2 | 2.3.2 |
| python | pillow | >= 0 < 2.3.0-1ubuntu3.3 | 2.3.0-1ubuntu3.3 |
| python | pillow | >= 0 < 2.3.0-1ubuntu3.2 | 2.3.0-1ubuntu3.2 |
| python | pillow | >= 2.5 < 2.5.2 | 2.5.2 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Pillow denial of service via Crafted Block Size
osv·2022-05-14
CVE-2014-3589 [HIGH] Pillow denial of service via Crafted Block Size
Pillow denial of service via Crafted Block Size
`PIL/IcnsImagePlugin.py` in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.
GHSA
Pillow denial of service via Crafted Block Size
ghsa·2022-05-14
CVE-2014-3589 [HIGH] CWE-20 Pillow denial of service via Crafted Block Size
Pillow denial of service via Crafted Block Size
`PIL/IcnsImagePlugin.py` in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.
OSV
Pillow regression
osv·2016-09-30·CVSS 5.0
CVE-2014-9601 [MEDIUM] Pillow regression
Pillow regression
USN-3090-1 fixed vulnerabilities in Pillow. The patch to fix CVE-2014-9601
caused a regression which resulted in failures when processing certain
png images. This update temporarily reverts the security fix for CVE-2014-9601
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorrectly handled certain malformed
FLI,
OSV
Pillow vulnerabilities
osv·2016-09-27·CVSS 5.0
CVE-2014-9601 [MEDIUM] Pillow vulnerabilities
Pillow vulnerabilities
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorrectly handled certain malformed
FLI, Tiff, and PhotoCD files. A remote attacker could use this issue to
cause Pillow to crash, resulting in a denial of service.
(CVE-2016-0740, CVE-2016-0775, CVE-2016-2533)
OSV
CVE-2014-3589: PIL/IcnsImagePlugin
osv·2014-08-25·CVSS 5.0
CVE-2014-3589 [MEDIUM] CVE-2014-3589: PIL/IcnsImagePlugin
PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.
Ubuntu
Pillow regresssion
vendor_ubuntu·2016-09-30·CVSS 5.0
CVE-2014-9601 [MEDIUM] Pillow regresssion
Title: Pillow regresssion
Summary: Pillow regresssion
USN-3090-1 fixed vulnerabilities in Pillow. The patch to fix CVE-2014-9601
caused a regression which resulted in failures when processing certain
png images. This update temporarily reverts the security fix for CVE-2014-9601
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorr
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2016-09-27·CVSS 5.0
CVE-2014-3589 [MEDIUM] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Pillow could be made to crash if it received specially crafted input or opened
a specially crafted file.
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorrectly handled certain malformed
FLI, Tiff, and PhotoCD files. A remote attacker could use this issue to
cause Pillow to crash, resulting in a denial of service.
(CVE-2016-0740, CVE-2016-0775, CVE-2016-2533)
Instructions: In general
Ubuntu
Python Imaging Library vulnerabilities
vendor_ubuntu·2016-09-15·CVSS 5.0
CVE-2014-3589 [MEDIUM] Python Imaging Library vulnerabilities
Title: Python Imaging Library vulnerabilities
Summary: Python Imaging Libary could be made to crash if it received specially crafted
input or opened a specially crafted file.
Eric Soroos discovered that the Python Imaging Library incorrectly handled
certain malformed FLI or PhotoCD files. A remote attacker could use this
issue to cause Python Imaging Library to crash, resulting in a denial of
service. (CVE-2016-0775, CVE-2016-2533)
Andrew Drake discovered that the Python Imaging Libray incorrectly validated
input. A remote attacker could use this to cause Python Imaging Library to
crash, resulting in a denial of service. (CVE-2014-3589)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-imaging: DoS in IcnsImagePlugin
vendor_redhat·2014-08-13·CVSS 5.0
CVE-2014-3589 [MEDIUM] CWE-835 python-imaging: DoS in IcnsImagePlugin
python-imaging: DoS in IcnsImagePlugin
PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.
Package: python-imaging (Red Hat Enterprise Linux 5) - Will not fix
Package: python-imaging (Red Hat Enterprise Linux 6) - Will not fix
Package: python-pillow (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2014-3589: pillow - PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 a...
vendor_debian·2014·CVSS 5.0
CVE-2014-3589 [MEDIUM] CVE-2014-3589: pillow - PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 a...
PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.
Scope: local
bookworm: resolved (fixed in 2.5.3-1)
bullseye: resolved (fixed in 2.5.3-1)
forky: resolved (fixed in 2.5.3-1)
sid: resolved (fixed in 2.5.3-1)
trixie: resolved (fixed in 2.5.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3589 python26-imaging: python-pillow: DoS in IcnsImagePlugin [epel-5]
bugzilla·2014-11-10·CVSS 5.0
CVE-2014-3589 [MEDIUM] CVE-2014-3589 python26-imaging: python-pillow: DoS in IcnsImagePlugin [epel-5]
CVE-2014-3589 python26-imaging: python-pillow: DoS in IcnsImagePlugin [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-5 tracking bug for python26-imaging: see bloc
Bugzilla
CVE-2014-3589 python-pillow: DoS in IcnsImagePlugin [fedora-all]
bugzilla·2014-08-16·CVSS 5.0
CVE-2014-3589 [MEDIUM] CVE-2014-3589 python-pillow: DoS in IcnsImagePlugin [fedora-all]
CVE-2014-3589 python-pillow: DoS in IcnsImagePlugin [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While
Bugzilla
CVE-2014-3589 python-pillow, python-imaging: DoS in IcnsImagePlugin
bugzilla·2014-08-16·CVSS 5.0
CVE-2014-3589 [MEDIUM] CVE-2014-3589 python-pillow, python-imaging: DoS in IcnsImagePlugin
CVE-2014-3589 python-pillow, python-imaging: DoS in IcnsImagePlugin
A denial of service vulnerability was reported in the Python Image Library and all versions of its fork, Pillow. If a user were able to supply date to the Image.open routine or similar APIs they could cause the application to crash due to inadequate input validation in the IcnsImagePlugin module. This has been corrected in upstream version 2.3.2 [1] and 2.5.2 [2]; a patch is available [3].
[1] https://pypi.python.org/pypi/Pillow/2.3.2
[2] https://pypi.python.org/pypi/Pillow/2.5.2
[3] https://github.com/python-pillow/Pillow/commit/205e056f8f9b06ed7b925cf8aa0874bc4aaf8a7d
Acknowledgements:
Red Hat would like to thank Andrew Drake of Dropbox for reporting this issue.
Discussion:
Created python-pillow tracking bugs for
http://lists.opensuse.org/opensuse-updates/2015-04/msg00056.htmlhttp://secunia.com/advisories/59825http://www.debian.org/security/2014/dsa-3009https://github.com/python-pillow/Pillow/commit/205e056f8f9b06ed7b925cf8aa0874bc4aaf8a7dhttps://pypi.python.org/pypi/Pillow/2.3.2https://pypi.python.org/pypi/Pillow/2.5.2http://lists.opensuse.org/opensuse-updates/2015-04/msg00056.htmlhttp://secunia.com/advisories/59825http://www.debian.org/security/2014/dsa-3009https://github.com/python-pillow/Pillow/commit/205e056f8f9b06ed7b925cf8aa0874bc4aaf8a7dhttps://pypi.python.org/pypi/Pillow/2.3.2https://pypi.python.org/pypi/Pillow/2.5.2
2014-08-25
Published