CVE-2019-19911
published 2020-01-05CVE-2019-19911: There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of…
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.12%
79.8th percentile
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | pillow | < pillow 7.0.0-1 (bookworm) | pillow 7.0.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| paloalto | pan-os | — | — |
| python | pillow | < 6.2.2 | 6.2.2 |
| python | pillow | >= 0 < 7.0.0-1 | 7.0.0-1 |
| python | pillow | >= 0 < 7.0.0-1 | 7.0.0-1 |
| python | pillow | >= 0 < 7.0.0-1 | 7.0.0-1 |
| python | pillow | >= 0 < 7.0.0-1 | 7.0.0-1 |
| python | pillow | >= 0 < 6.2.2 | 6.2.2 |
| python | pillow | >= 0 < 3.1.2-0ubuntu1.3 | 3.1.2-0ubuntu1.3 |
| python | pillow | >= 0 < 5.1.0-1ubuntu0.2 | 5.1.0-1ubuntu0.2 |
| python | pillow | >= 0 < 2.3.0-1ubuntu3.4+esm1 | 2.3.0-1ubuntu3.4+esm1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2020-02-06·CVSS 7.5
CVE-2019-16865 [HIGH] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
It was discovered that Pillow incorrectly handled certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2019-16865, CVE-2019-19911)
It was discovered that Pillow incorrectly handled certain images.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-5312)
It was discovered that Pillow incorrectly handled certain TIFF images.
An attacker could possibly use this issue to cause a crash. This issue
only affected Ubuntu 19.10. (CVE-2020-5310)
It was discovered that Pillow incorrectly handled certain SGI images.
An attacker could possibly use this issue to execute arbitrary code or
cause a crash. This issue only affected Ubuntu 18.04 and Ubun
Red Hat
python-pillow: uncontrolled resource consumption in FpxImagePlugin.py
vendor_redhat·2020-01-03·CVSS 7.5
CVE-2019-19911 [HIGH] CWE-400 python-pillow: uncontrolled resource consumption in FpxImagePlugin.py
python-pillow: uncontrolled resource consumption in FpxImagePlugin.py
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.
A denial of service vulnerability was found in Pillow in versions before 6.2.2, where the FpxImagePlugin.py file calls the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows systems running 32-bit Python, this flaw results in an OverflowError or MemoryError due to the 2 GB limit. On Linux systems running
Debian
CVE-2019-19911: pillow - There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py ...
vendor_debian·2019·CVSS 7.5
CVE-2019-19911 [HIGH] CVE-2019-19911: pillow - There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py ...
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.
Scope: local
bookworm: resolved (fixed in 7.0.0-1)
bullseye: resolved (fixed in 7.0.0-1)
forky: resolved (fixed in 7.0.0-1)
sid: resolved (fixed in 7.0.0-1)
trixie: resolved (fixed in 7.0.0-1)
OSV
Uncontrolled Resource Consumption in Pillow
osv·2020-04-01
CVE-2019-19911 [HIGH] Uncontrolled Resource Consumption in Pillow
Uncontrolled Resource Consumption in Pillow
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.
GHSA
Uncontrolled Resource Consumption in Pillow
ghsa·2020-04-01
CVE-2019-19911 [HIGH] CWE-190 Uncontrolled Resource Consumption in Pillow
Uncontrolled Resource Consumption in Pillow
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.
OSV
pillow vulnerabilities
osv·2020-02-06·CVSS 7.5
CVE-2019-16865 [HIGH] pillow vulnerabilities
pillow vulnerabilities
It was discovered that Pillow incorrectly handled certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2019-16865, CVE-2019-19911)
It was discovered that Pillow incorrectly handled certain images.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-5312)
It was discovered that Pillow incorrectly handled certain TIFF images.
An attacker could possibly use this issue to cause a crash. This issue
only affected Ubuntu 19.10. (CVE-2020-5310)
It was discovered that Pillow incorrectly handled certain SGI images.
An attacker could possibly use this issue to execute arbitrary code or
cause a crash. This issue only affected Ubuntu 18.04 and Ubuntu 19.10.
(CVE-2020-5311)
It was discovered that Pillow incorr
OSV
CVE-2019-19911: There is a DoS vulnerability in Pillow before 6
osv·2020-01-05·CVSS 7.5
CVE-2019-19911 [HIGH] CVE-2019-19911: There is a DoS vulnerability in Pillow before 6
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-19911 python-pillow: Out of memory issue in FpxImagePlugin.py [fedora-all]
bugzilla·2020-02-06·CVSS 7.5
CVE-2019-19911 [HIGH] CVE-2019-19911 python-pillow: Out of memory issue in FpxImagePlugin.py [fedora-all]
CVE-2019-19911 python-pillow: Out of memory issue in FpxImagePlugin.py [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2019-19911 python3-pillow: python-pillow: Out of memory issue in FpxImagePlugin.py [epel-7]
bugzilla·2020-02-06·CVSS 7.5
CVE-2019-19911 [HIGH] CVE-2019-19911 python3-pillow: python-pillow: Out of memory issue in FpxImagePlugin.py [epel-7]
CVE-2019-19911 python3-pillow: python-pillow: Out of memory issue in FpxImagePlugin.py [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following templat
Bugzilla
CVE-2019-19911 python-pillow: uncontrolled resource consumption in FpxImagePlugin.py
bugzilla·2020-01-09·CVSS 7.5
CVE-2019-19911 [HIGH] CVE-2019-19911 python-pillow: uncontrolled resource consumption in FpxImagePlugin.py
CVE-2019-19911 python-pillow: uncontrolled resource consumption in FpxImagePlugin.py
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.
References:
https://pillow.readthedocs.io/en/stable/releasenotes/6.2.2.html
Discussion:
This seems to be the fix for this flaw:
https://github.com/python-pillow/Pillow/commit/774e53bb132461d8d5ebefec1162e29ec0ebc63d
---
The flaw is in the FpxImagePlugin file, which can be loaded only if the python module "olefile" is present
CWE
Uncontrolled Resource Consumption
mitre_cwe
CWE-400 Uncontrolled Resource Consumption
CWE-400: Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
Modes of Introduction:
Phase: Operation
Note: The product could be operated in a system or environment with lower resource limits than expected, which might make it easier for attackers to consume all available resources.
Phase: System Configuration
Note: The product could be configured with lower resource limits than expected, which might make it easier for attackers to consume all available resources.
Phase: Architecture and Design
Note: The designer might not consider how to handle and throttle excessive resource requests, which typically requires careful planning to handle more gracefully than a crash or exit.
Phase: Implementation
Note: There are at
CWE
Improper Control of a Resource Through its Lifetime
mitre_cwe·CVSS 9.8
[CRITICAL] CWE-664 Improper Control of a Resource Through its Lifetime
CWE-664: Improper Control of a Resource Through its Lifetime
The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.
Resources often have explicit instructions on how to be created, used and destroyed. When code does not follow these instructions, it can lead to unexpected behaviors and potentially exploitable states. Even without explicit instructions, various principles are expected to be adhered to, such as "Do not use an object until after its creation is complete," or "do not use an object after it has been slated for destruction."
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Other. Impact: Other.
Detection Methods:
Automated Static Analysis: Use Static analysis tools to chec
CWE
Memory Allocation with Excessive Size Value
mitre_cwe
CWE-789 Memory Allocation with Excessive Size Value
CWE-789: Memory Allocation with Excessive Size Value
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Availability. Impact: DoS: Resource Consumption (Memory). Not controlling memory allocation can result in a request for too much system memory, possibly leading to a crash of the application due to out-of-memory conditions, or the consumption of a large amount of memory on the system.
Detection Methods:
Fuzzing: Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code w
CWE
Allocation of Resources Without Limits or Throttling
mitre_cwe
CWE-770 Allocation of Resources Without Limits or Throttling
CWE-770: Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Modes of Introduction:
Phase: Architecture and Design
Note: OMISSION: This weakness is caused by missing a security tactic during the architecture and design phase.
Phase: Implementation
Phase: Operation
Phase: System Configuration
Common Consequences:
Scope: Availability. Impact: DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Resource Consumption (Other). When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be
CWE
Integer Overflow or Wraparound
mitre_cwe
CWE-190 Integer Overflow or Wraparound
CWE-190: Integer Overflow or Wraparound
The product performs a calculation that can
produce an integer overflow or wraparound when the logic
assumes that the resulting value will always be larger than
the original value. This occurs when an integer value is
incremented to a value that is too large to store in the
associated representation. When this occurs, the value may
become a very small or negative number.
Modes of Introduction:
Phase: Implementation
Note: This weakness may become security critical when determining the offset or size in behaviors such as memory allocation, copying, and concatenation.
Common Consequences:
Scope: Availability. Impact: DoS: Crash, Exit, or Restart, DoS: Resource Consumption (Memory), DoS: Instability. This weakness can generally lead to undefined behav
CWE
Improper Validation of Specified Quantity in Input
mitre_cwe
CWE-1284 Improper Validation of Specified Quantity in Input
CWE-1284: Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
Specified quantities include size, length, frequency, price, rate, number of operations, time, and others. Code may rely on specified quantities to allocate resources, perform calculations, control iteration, etc.
Modes of Introduction:
Phase: Implementation
Note: Since quantities are often used to affect resource allocation or process financial data, they are often present in many places in the code.
Common Consequences:
Scope: Other, Integrity, Availability. Impact: Varies by Context, DoS: Resource Consumption (CPU), Modify Memory, Read M
CWE
Write-what-where Condition
mitre_cwe
CWE-123 Write-what-where Condition
CWE-123: Write-what-where Condition
Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Integrity, Confidentiality, Availability, Access Control. Impact: Modify Memory, Execute Unauthorized Code or Commands, Gain Privileges or Assume Identity, DoS: Crash, Exit, or Restart, Bypass Protection Mechanism. Clearly, write-what-where conditions can be used to write data to areas of memory outside the scope of a policy. Also, they almost invariably can be used to execute arbitrary code, which is usually outside the scope of a program's implicit security policy. If the attacker can overwrite a pointer's worth of memory (usually 32 o
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3DUMIBUYGJRAVJCTFUWBRLVQKOUTVX5P/https://pillow.readthedocs.io/en/stable/releasenotes/6.2.2.htmlhttps://usn.ubuntu.com/4272-1/https://www.debian.org/security/2020/dsa-4631https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3DUMIBUYGJRAVJCTFUWBRLVQKOUTVX5P/https://pillow.readthedocs.io/en/stable/releasenotes/6.2.2.htmlhttps://usn.ubuntu.com/4272-1/https://www.debian.org/security/2020/dsa-4631
2020-01-05
Published