Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Ubuntu 23.10 USN-6618-1: Severe Pillow DoS and Code Execution Risks

ubuntu
Calendar Grey January 30, 2024
Scroller Ubuntu
Security Update USN-6719-2 addresses vulnerabilities in the OpenSSL package affecting the integrity and safety of Ubuntu systems.
Several security issues were fixed in Pillow.

Summary

Several security issues were fixed in Pillow.

Software Description:

- pillow: Python Imaging Library

Details:

It was discovered that Pillow incorrectly handled certain long text

arguments. An attacker could possibly use this issue to cause Pillow to

consume resources, leading to a denial of service. This issue only affected

Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2023-44271)

Duarte Santos discovered that Pillow incorrectly handled the environment

parameter to PIL.ImageMath.eval. An attacker could possibly use this issue

to execute arbitrary code. (CVE-2023-50447)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.10:
   python3-pil                     10.0.0-1ubuntu0.1

Ubuntu 22.04 LTS:
   python3-pil                     9.0.1-1ubuntu0.2

Ubuntu 20.04 LTS:
   python3-pil                     7.0.0-4ubuntu0.8

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6618-1

CVE-2023-44271, CVE-2023-50447

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-6618-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.