CVE-2014-9601
published 2015-01-16CVE-2014-9601: Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.43%
91.8th percentile
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pillow | < pillow 2.6.1-2 (bookworm) | pillow 2.6.1-2 (bookworm) |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| python | pillow | <= 2.6.2 | — |
| python | pillow | >= 0 < 2.6.1-2 | 2.6.1-2 |
| python | pillow | >= 0 < 2.6.1-2 | 2.6.1-2 |
| python | pillow | >= 0 < 2.6.1-2 | 2.6.1-2 |
| python | pillow | >= 0 < 2.6.1-2 | 2.6.1-2 |
| python | pillow | >= 0 < 2.7.0 | 2.7.0 |
| python | pillow | >= 0 < 2.3.0-1ubuntu3.3 | 2.3.0-1ubuntu3.3 |
| python | pillow | >= 0 < 2.3.0-1ubuntu3.2 | 2.3.0-1ubuntu3.2 |
| python | pillow | >= 0 < 2.3.0-1ubuntu3.4 | 2.3.0-1ubuntu3.4 |
| python | pillow | >= 0 < 3.1.2-0ubuntu1.1 | 3.1.2-0ubuntu1.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Pillow denial of service via PNG bomb
osv·2022-05-14
CVE-2014-9601 [HIGH] Pillow denial of service via PNG bomb
Pillow denial of service via PNG bomb
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
GHSA
Pillow denial of service via PNG bomb
ghsa·2022-05-14
CVE-2014-9601 [HIGH] CWE-20 Pillow denial of service via PNG bomb
Pillow denial of service via PNG bomb
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
OSV
pillow vulnerabilities
osv·2017-03-13·CVSS 5.0
CVE-2014-9601 [MEDIUM] pillow vulnerabilities
pillow vulnerabilities
It was discovered that Pillow incorrectly handled certain compressed text
chunks in PNG images. A remote attacker could possibly use this issue to
cause Pillow to crash, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS. (CVE-2014-9601)
Cris Neckar discovered that Pillow incorrectly handled certain malformed
images. A remote attacker could use this issue to cause Pillow to crash,
resulting in a denial of service, or possibly obtain sensitive information.
(CVE-2016-9189)
Cris Neckar discovered that Pillow incorrectly handled certain malformed
images. A remote attacker could use this issue to cause Pillow to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-9190)
OSV
Pillow regression
osv·2016-09-30·CVSS 5.0
CVE-2014-9601 [MEDIUM] Pillow regression
Pillow regression
USN-3090-1 fixed vulnerabilities in Pillow. The patch to fix CVE-2014-9601
caused a regression which resulted in failures when processing certain
png images. This update temporarily reverts the security fix for CVE-2014-9601
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorrectly handled certain malformed
FLI,
OSV
Pillow vulnerabilities
osv·2016-09-27·CVSS 5.0
CVE-2014-9601 [MEDIUM] Pillow vulnerabilities
Pillow vulnerabilities
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorrectly handled certain malformed
FLI, Tiff, and PhotoCD files. A remote attacker could use this issue to
cause Pillow to crash, resulting in a denial of service.
(CVE-2016-0740, CVE-2016-0775, CVE-2016-2533)
OSV
CVE-2014-9601: Pillow before 2
osv·2015-01-16·CVSS 5.0
CVE-2014-9601 [MEDIUM] CVE-2014-9601: Pillow before 2
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2017-03-13·CVSS 5.0
CVE-2014-9601 [MEDIUM] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
It was discovered that Pillow incorrectly handled certain compressed text
chunks in PNG images. A remote attacker could possibly use this issue to
cause Pillow to crash, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS. (CVE-2014-9601)
Cris Neckar discovered that Pillow incorrectly handled certain malformed
images. A remote attacker could use this issue to cause Pillow to crash,
resulting in a denial of service, or possibly obtain sensitive information.
(CVE-2016-9189)
Cris Neckar discovered that Pillow incorrectly handled certain malformed
images. A remote attacker could use this issue to cause Pillow to crash,
resulting in a denial of service, or possibly execute arbitrary
Ubuntu
Python Imaging Library vulnerabilities
vendor_ubuntu·2017-03-13·CVSS 5.0
CVE-2014-9601 [MEDIUM] Python Imaging Library vulnerabilities
Title: Python Imaging Library vulnerabilities
Summary: Several security issues were fixed in the Python Imaging Library.
It was discovered that the Python Imaging Library incorrectly handled
certain compressed text chunks in PNG images. A remote attacker could
possibly use this issue to cause the Python Imaging Library to crash,
resulting in a denial of service. (CVE-2014-9601)
Cris Neckar discovered that the Python Imaging Library incorrectly handled
certain malformed images. A remote attacker could use this issue to cause
the Python Imaging Library to crash, resulting in a denial of service, or
possibly obtain sensitive information. (CVE-2016-9189)
Cris Neckar discovered that the Python Imaging Library incorrectly handled
certain malformed images. A remote attacker could use this iss
Ubuntu
Pillow regresssion
vendor_ubuntu·2016-09-30·CVSS 5.0
CVE-2014-9601 [MEDIUM] Pillow regresssion
Title: Pillow regresssion
Summary: Pillow regresssion
USN-3090-1 fixed vulnerabilities in Pillow. The patch to fix CVE-2014-9601
caused a regression which resulted in failures when processing certain
png images. This update temporarily reverts the security fix for CVE-2014-9601
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorr
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2016-09-27·CVSS 5.0
CVE-2014-3589 [MEDIUM] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Pillow could be made to crash if it received specially crafted input or opened
a specially crafted file.
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorrectly handled certain malformed
FLI, Tiff, and PhotoCD files. A remote attacker could use this issue to
cause Pillow to crash, resulting in a denial of service.
(CVE-2016-0740, CVE-2016-0775, CVE-2016-2533)
Instructions: In general
Red Hat
python-pillow: potential denial-of-service during PNG decompression
vendor_redhat·2014-12-31·CVSS 5.0
CVE-2014-9601 [MEDIUM] CWE-770 python-pillow: potential denial-of-service during PNG decompression
python-pillow: potential denial-of-service during PNG decompression
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
Package: python-imaging (Red Hat Enterprise Linux 5) - Will not fix
Package: python-imaging (Red Hat Enterprise Linux 6) - Will not fix
Package: python-pillow (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2014-9601: pillow - Pillow before 2.7.0 allows remote attackers to cause a denial of service via a c...
vendor_debian·2014·CVSS 5.0
CVE-2014-9601 [MEDIUM] CVE-2014-9601: pillow - Pillow before 2.7.0 allows remote attackers to cause a denial of service via a c...
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
Scope: local
bookworm: resolved (fixed in 2.6.1-2)
bullseye: resolved (fixed in 2.6.1-2)
forky: resolved (fixed in 2.6.1-2)
sid: resolved (fixed in 2.6.1-2)
trixie: resolved (fixed in 2.6.1-2)
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148442.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00056.htmlhttp://pillow.readthedocs.org/releasenotes/2.7.0.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.securityfocus.com/bid/77758https://github.com/python-pillow/Pillow/pull/1060https://www.djangoproject.com/weblog/2015/jan/02/pillow-security-release/http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148442.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00056.htmlhttp://pillow.readthedocs.org/releasenotes/2.7.0.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.securityfocus.com/bid/77758https://github.com/python-pillow/Pillow/pull/1060https://www.djangoproject.com/weblog/2015/jan/02/pillow-security-release/
2015-01-16
Published