CVE-2023-44271
published 2023-11-03CVE-2023-44271: An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a…
PriorityP434high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.04%
60.1th percentile
An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pillow | < pillow 9.4.0-1.1+deb12u1 (bookworm) | pillow 9.4.0-1.1+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| paloalto | pan-os | — | — |
| python | pillow | < 10.0.0 | 10.0.0 |
| python | pillow | >= 0 < 8.1.2+dfsg-0.3+deb11u2 | 8.1.2+dfsg-0.3+deb11u2 |
| python | pillow | >= 0 < 9.4.0-1.1+deb12u1 | 9.4.0-1.1+deb12u1 |
| python | pillow | >= 0 < 10.0.0-1 | 10.0.0-1 |
| python | pillow | >= 0 < 10.0.0-1 | 10.0.0-1 |
| python | pillow | >= 0 < 10.0.0 | 10.0.0 |
| python | pillow | >= 0 < 7.0.0-4ubuntu0.8 | 7.0.0-4ubuntu0.8 |
| python | pillow | >= 0 < 9.0.1-1ubuntu0.2 | 9.0.1-1ubuntu0.2 |
| python | pillow | >= 0 < 2.3.0-1ubuntu3.4+esm5 | 2.3.0-1ubuntu3.4+esm5 |
| python | pillow | >= 0 < 3.1.2-0ubuntu1.6+esm3 | 3.1.2-0ubuntu1.6+esm3 |
| python | pillow | >= 0 < 5.1.0-1ubuntu0.8+esm2 | 5.1.0-1ubuntu0.8+esm2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv9.1CRITICAL
vendor_ubuntu9.1CRITICAL
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
pillow vulnerabilities
osv·2026-03-31·CVSS 9.1
CVE-2021-25287 [CRITICAL] pillow vulnerabilities
pillow vulnerabilities
It was discovered that Pillow did not correctly handle reading J2K files,
which could lead to an out-of-bounds read vulnerability. If a user or
automated system were tricked into opening a specially crafted file, an
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 16.04 LTS. (CVE-2021-25287, CVE-2021-25288)
It was discovered that Pillow did not correctly handle certain integer
arithmetic, which could lead to a buffer overflow. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS. (CVE-2021-25290)
It was discovered that Pillow did not correctly perform bounds checking
for certain operations. An attacker could possibly use this i
OSV
pillow vulnerabilities
osv·2024-01-30·CVSS 7.5
CVE-2023-44271 [HIGH] pillow vulnerabilities
pillow vulnerabilities
It was discovered that Pillow incorrectly handled certain long text
arguments. An attacker could possibly use this issue to cause Pillow to
consume resources, leading to a denial of service. This issue only affected
Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2023-44271)
Duarte Santos discovered that Pillow incorrectly handled the environment
parameter to PIL.ImageMath.eval. An attacker could possibly use this issue
to execute arbitrary code. (CVE-2023-50447)
OSV
CVE-2023-44271: An issue was discovered in Pillow before 10
osv·2023-11-03·CVSS 7.5
CVE-2023-44271 [HIGH] CVE-2023-44271: An issue was discovered in Pillow before 10
An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
OSV
Pillow Denial of Service vulnerability
osv·2023-11-03
CVE-2023-44271 [HIGH] Pillow Denial of Service vulnerability
Pillow Denial of Service vulnerability
An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
GHSA
Pillow Denial of Service vulnerability
ghsa·2023-11-03
CVE-2023-44271 [HIGH] CWE-400 Pillow Denial of Service vulnerability
Pillow Denial of Service vulnerability
An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2026-03-31·CVSS 9.1
CVE-2023-50447 [CRITICAL] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
It was discovered that Pillow did not correctly handle reading J2K files,
which could lead to an out-of-bounds read vulnerability. If a user or
automated system were tricked into opening a specially crafted file, an
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 16.04 LTS. (CVE-2021-25287, CVE-2021-25288)
It was discovered that Pillow did not correctly handle certain integer
arithmetic, which could lead to a buffer overflow. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS. (CVE-2021-25290)
It was discovered that Pillow did not correctly perform bounds checkin
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Common (Pillow) — CVE-2023-44271
vendor_oracle·2024-04-15·CVSS 7.5
CVE-2023-44271 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Common (Pillow) — CVE-2023-44271
Oracle Oracle Financial Services Applications Risk Matrix: Common (Pillow) vulnerability
CVE: CVE-2023-44271
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2024-01-30·CVSS 7.5
CVE-2023-44271 [HIGH] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
It was discovered that Pillow incorrectly handled certain long text
arguments. An attacker could possibly use this issue to cause Pillow to
consume resources, leading to a denial of service. This issue only affected
Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2023-44271)
Duarte Santos discovered that Pillow incorrectly handled the environment
parameter to PIL.ImageMath.eval. An attacker could possibly use this issue
to execute arbitrary code. (CVE-2023-50447)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-pillow: uncontrolled resource consumption when textlength in an ImageDraw instance operates on a long text argument
vendor_redhat·2023-06-30·CVSS 7.5
CVE-2023-44271 [HIGH] CWE-400 python-pillow: uncontrolled resource consumption when textlength in an ImageDraw instance operates on a long text argument
python-pillow: uncontrolled resource consumption when textlength in an ImageDraw instance operates on a long text argument
An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
A flaw was found in Pillow. A denial of service issue uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for TrueType in ImageFont when text length in an ImageDraw instance operates on a long text argument.
Statement: This security vulnerability is categorized as
Debian
CVE-2023-44271: pillow - An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that ...
vendor_debian·2023·CVSS 7.5
CVE-2023-44271 [HIGH] CVE-2023-44271: pillow - An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that ...
An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
Scope: local
bookworm: resolved (fixed in 9.4.0-1.1+deb12u1)
bullseye: resolved (fixed in 8.1.2+dfsg-0.3+deb11u2)
forky: resolved (fixed in 10.0.0-1)
sid: resolved (fixed in 10.0.0-1)
trixie: resolved (fixed in 10.0.0-1)
No detection rules found.
No public exploits indexed.
https://devhub.checkmarx.com/cve-details/CVE-2023-44271/https://github.com/python-pillow/Pillow/commit/1fe1bb49c452b0318cad12ea9d97c3bef188e9a7https://github.com/python-pillow/Pillow/pull/7244https://lists.debian.org/debian-lts-announce/2024/03/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N2JOEDUJDQLCUII2LQYZYSM7RJL2I3P4/https://devhub.checkmarx.com/cve-details/CVE-2023-44271/https://github.com/python-pillow/Pillow/commit/1fe1bb49c452b0318cad12ea9d97c3bef188e9a7https://github.com/python-pillow/Pillow/pull/7244https://lists.debian.org/debian-lts-announce/2024/03/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N2JOEDUJDQLCUII2LQYZYSM7RJL2I3P4/
2023-11-03
Published