Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 PyPI

Pillow subject to DoS via SAMPLESPERPIXEL tag

GHSA-q4mp-jvh2-76fj · BIT-pillow-2022-45199 · CVE-2022-45199 · PYSEC-2022-42980

Published · Modified

Description

Pillow starting with 9.2.0 and prior to 9.3.0 allows denial of service via SAMPLESPERPIXEL. A large value in the SAMPLESPERPIXEL tag could lead to a memory and runtime DOS in TiffImagePlugin.py when setting up the context for image decoding. This issue has been patched in version 9.3.0.

Ready to move

Start Securing

Free, no credit card | First findings in minutes