DEBIAN-CVE-2019-16865

Source
https://security-tracker.debian.org/tracker/CVE-2019-16865
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2019-16865.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2019-16865
Upstream
Published
2019-10-04T22:15:11Z
Modified
2025-09-19T06:19:38Z
Summary
[none]
Details

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

References

Affected packages

Debian:11 / pillow

Package

Name
pillow
Purl
pkg:deb/debian/pillow?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.2.0-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / pillow

Package

Name
pillow
Purl
pkg:deb/debian/pillow?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.2.0-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / pillow

Package

Name
pillow
Purl
pkg:deb/debian/pillow?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.2.0-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:14 / pillow

Package

Name
pillow
Purl
pkg:deb/debian/pillow?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.2.0-1

Ecosystem specific

{
    "urgency": "low"
}