CVE-2014-3589

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.

References

http://lists.opensuse.org/opensuse-updates/2015-04/msg00056.html

http://secunia.com/advisories/59825

http://www.debian.org/security/2014/dsa-3009

https://github.com/python-pillow/Pillow/commit/205e056f8f9b06ed7b925cf8aa0874bc4aaf8a7d

https://pypi.python.org/pypi/Pillow/2.3.2

https://pypi.python.org/pypi/Pillow/2.5.2

Details

Source: MITRE

Published: 2014-08-25

Updated: 2018-10-30

Type: CWE-20

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

Tenable Plugins

View all (16 total)

IDNameProductFamilySeverity
136235EulerOS Virtualization for ARM 64 3.0.2.0 : python-pillow (EulerOS-SA-2020-1532)NessusHuawei Local Security Checks
critical
135635EulerOS Virtualization 3.0.2.2 : python-pillow (EulerOS-SA-2020-1473)NessusHuawei Local Security Checks
critical
132368EulerOS 2.0 SP5 : python-pillow (EulerOS-SA-2019-2701)NessusHuawei Local Security Checks
critical
132189EulerOS 2.0 SP3 : python-pillow (EulerOS-SA-2019-2654)NessusHuawei Local Security Checks
high
131591EulerOS 2.0 SP2 : python-pillow (EulerOS-SA-2019-2437)NessusHuawei Local Security Checks
high
93827Ubuntu 14.04 LTS : Pillow regression (USN-3090-2)NessusUbuntu Local Security Checks
medium
93775Ubuntu 14.04 LTS : Pillow vulnerabilities (USN-3090-1)NessusUbuntu Local Security Checks
medium
93559Ubuntu 12.04 LTS : python-imaging vulnerabilities (USN-3080-1)NessusUbuntu Local Security Checks
medium
83160openSUSE Security Update : python-Pillow (openSUSE-2015-337)NessusSuSE Local Security Checks
medium
82352Mandriva Linux Security Advisory : python-pillow (MDVSA-2015:099)NessusMandriva Local Security Checks
critical
82188Debian DLA-41-1 : python-imaging security updateNessusDebian Local Security Checks
medium
80747Oracle Solaris Third-Party Patch Update : py_pil (cve_2014_3589_input_validation)NessusSolaris Local Security Checks
medium
77642Mandriva Linux Security Advisory : python-imaging (MDVSA-2014:163)NessusMandriva Local Security Checks
medium
77397Fedora 20 : python-pillow-2.2.1-5.fc20 (2014-9540)NessusFedora Local Security Checks
medium
77395Fedora 19 : python-pillow-2.0.0-14.gitd1c6db8.fc19 (2014-9536)NessusFedora Local Security Checks
medium
77343Debian DSA-3009-1 : python-imaging - security updateNessusDebian Local Security Checks
medium