Integer Overflow or Wraparound Affecting pillow package, versions [,6.2.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
2.12% (80th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Integer Overflow or Wraparound vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-PILLOW-2371745
  • published26 Jan 2022
  • disclosed5 Jan 2020
  • creditUnknown

Introduced: 5 Jan 2020

CVE-2019-19911  (opens in a new tab)
CWE-190  (opens in a new tab)

How to fix?

Upgrade pillow to version 6.2.2 or higher.

Overview

Affected versions of this package are vulnerable to Integer Overflow or Wraparound. There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.

CVSS Base Scores

version 3.1