Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29559
HistoryMar 04, 2021 - 2:24 a.m.

Denial Of Service (DoS)

2021-03-0402:24:08
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18
pillow
software
vulnerability
denial of service
image formats

EPSS

0.002

Percentile

64.4%

pillow is vulnerable to a denial of service. An attacker is able to send contained images in the ICNS, ICO, and BLP container formats to cause huge memory allocations as it does not check the size of the contained image in those formats.