UBUNTU-CVE-2023-44271
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-44271
UBUNTU-CVE-2023-44271
Summary:
Details: An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
References: https://ubuntu.com/security/CVE-2023-44271, https://devhub.checkmarx.com/cve-details/CVE-2023-44271/, https://ubuntu.com/security/notices/USN-6618-1, https://www.cve.org/CVERecord?id=CVE-2023-44271, https://ubuntu.com/security/notices/USN-8135-1
Affected packages
Package
Name: pillow
Purl: pkg:deb/ubuntu/[email protected]+esm5?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
