UBUNTU-CVE-2014-9601
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-9601
UBUNTU-CVE-2014-9601
Summary:
Details: Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
References: https://ubuntu.com/security/CVE-2014-9601, https://www.djangoproject.com/weblog/2015/jan/02/pillow-security-release/, https://github.com/python-pillow/Pillow/pull/1060, http://pillow.readthedocs.org/releasenotes/2.7.0.html, https://ubuntu.com/security/notices/USN-3090-2, https://ubuntu.com/security/notices/USN-3090-1, https://ubuntu.com/security/notices/USN-3230-1, https://ubuntu.com/security/notices/USN-3229-1, https://www.cve.org/CVERecord?id=CVE-2014-9601
Affected packages
Package
Name: pillow
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
