Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Ubuntu 12.04 LTS USN-3080-1 Critical: Python Imaging Library DoS Threat

ubuntu
Calendar Grey September 15, 2016
Scroller Ubuntu
Security flaws in the Python Imaging Library found in Ubuntu 12.04 LTS may lead to service interruptions when manipulated by malicious users.
Python Imaging Library could be made to crash if it received specially crafted input or opened a specially crafted file.

Summary

Python Imaging Library could be made to crash if it received specially crafted

input or opened a specially crafted file.

Software Description:

- python-imaging: Python Imaging Library

Details:

Eric Soroos discovered that the Python Imaging Library incorrectly handled

certain malformed FLI or PhotoCD files. A remote attacker could use this

issue to cause Python Imaging Library to crash, resulting in a denial of

service. (CVE-2016-0775, CVE-2016-2533)

Andrew Drake discovered that the Python Imaging Library incorrectly validated

input. A remote attacker could use this to cause Python Imaging Library to

crash, resulting in a denial of service. (CVE-2014-3589)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  python-imaging                  1.1.7-4ubuntu0.12.04.2

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-3080-1

  CVE-2014-3589, CVE-2016-0775, CVE-2016-2533

Severity
critical
Lowest
Low
Medium
High
Critical

September 15, 2016

Package Information

  https://launchpad.net/ubuntu/+source/python-imaging/1.1.7-4ubuntu0.12.04.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.