CVE-2019-16865

unknown
Published 2019-10-22 · Modified 2023-11-08
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2
VIR risk

Description

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2019-16865

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2019-16865.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed6.2.0-1
debian debianbullseyefixed6.2.0-1
debian debianforkyfixed6.2.0-1
debian debiansidfixed6.2.0-1
debian debiantrixiefixed6.2.0-1

Package impact

EcosystemPackageVulnerableFixed
python PyPIpillow<6.2.06.2.0

References

Verify integrity in audit chain (admin only). AS-IS.