Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian: DSA-3009-1 Critical: Python Imaging DoS Due To Input Flaw

debian
Calendar Grey August 21, 2014
Debian Logo
Attention Debian users: A new patch for python-imaging has been released to address a vulnerability linked to poor input validation, which could allow Denial of Service via malicious images
Andrew Drake discovered that missing input sanitising in the icns decoder of the Python Imaging Library could result in denial of service if a malformed image is processed

Summary

Andrew Drake discovered that missing input sanitising in the icns decoder
of the Python Imaging Library could result in denial of service if a
malformed image is processed.

For the stable distribution (wheezy), this problem has been fixed in
version 1.1.7-4+deb7u1.

For the unstable distribution (sid), this problem has been fixed in
version 2.5.3-1 of the pillow source package.

We recommend that you upgrade your python-imaging packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: python-imaging
CVE ID: CVE-2014-3589

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here