Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38004
HistoryNov 15, 2022 - 8:16 a.m.

Denial Of Service (DoS)

2022-11-1508:16:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
pillow
vulnerability
tiffimageplugin
memory exhaustion
dos attacks

EPSS

0.002

Percentile

57.9%

Pillow is vulnerable to denial of service (DoS) attacks. The vulnerability is due to improper handling of the SAMPLESPERPIXEL tag in TiffImagePlugin.py, causing large values to lead to memory exhaustion.