Resource exhaustion in Pillow - CVE-2023-44271
Published: November 18, 2023
Vulnerability identifier: #VU83261
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-44271
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in ImageFont. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Pillow
Debian Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Anolis OS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Python 3 Module
openSUSE Leap
openEuler
Ubuntu
Fedora
PowerVC
Ansible Automation Platform
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Business Automation Workflow
Maximo Application Suite - Edge Data Collector
Cloud Pak for Network Automation
XtremIO X2
Oracle Banking Origination
Oracle Banking Liquidity Management
python-pillow
python-pillow-devel
python-pillow-doc
python-pillow-tk
python-pillow-sane
python-pillow-qt
python-pillow (Red Hat package)
python-Pillow-debuginfo
python-Pillow
python-Pillow-debugsource
python3-pillow
python3-pillow-devel
python3-pillow-tk
python3-pillow-doc
python3-pil (Ubuntu package)
python3-Pillow-tk-debuginfo
python3-Pillow-tk
python3-Pillow
python3-Pillow-debuginfo
pillow (Debian package)
python-pillow-debuginfo
python3-pillow-help
python3-pillow-qt
python-pillow-debugsource
python311-Pillow-tk
python311-Pillow-tk-debuginfo
python311-Pillow
python311-Pillow-debuginfo
dev-python/pillow
Debian Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Anolis OS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Python 3 Module
openSUSE Leap
openEuler
Ubuntu
Fedora
PowerVC
Ansible Automation Platform
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Business Automation Workflow
Maximo Application Suite - Edge Data Collector
Cloud Pak for Network Automation
XtremIO X2
Oracle Banking Origination
Oracle Banking Liquidity Management
python-pillow
python-pillow-devel
python-pillow-doc
python-pillow-tk
python-pillow-sane
python-pillow-qt
python-pillow (Red Hat package)
python-Pillow-debuginfo
python-Pillow
python-Pillow-debugsource
python3-pillow
python3-pillow-devel
python3-pillow-tk
python3-pillow-doc
python3-pil (Ubuntu package)
python3-Pillow-tk-debuginfo
python3-Pillow-tk
python3-Pillow
python3-Pillow-debuginfo
pillow (Debian package)
python-pillow-debuginfo
python3-pillow-help
python3-pillow-qt
python-pillow-debugsource
python311-Pillow-tk
python311-Pillow-tk-debuginfo
python311-Pillow
python311-Pillow-debuginfo
dev-python/pillow
How to mitigate CVE-2023-44271
Install updates from vendor's website.
Pillow - update to 10.0.0
Maximo Application Suite - Edge Data Collector - update to 8.11.3
python-pillow - update to 2.0.0-24.gitd1c6db8
python-pillow-devel - update to 2.0.0-24.gitd1c6db8
python-pillow-doc - update to 2.0.0-24.gitd1c6db8
python-pillow-tk - update to 2.0.0-24.gitd1c6db8
python-pillow-sane - update to 2.0.0-24.gitd1c6db8
python-pillow-qt - update to 2.0.0-24.gitd1c6db8
python-pillow (Red Hat package) - addressed in versions 2.0.0-24.gitd1c6db8.el7_9, 5.1.1-20.el8
Cloud Pak for Network Automation - update to 2.6.4
python-Pillow-debuginfo - addressed in versions 4.2.1-3.23.2, 5.2.0-3.20.1, 7.2.0-150300.3.3.1, 9.5.0-150400.5.6.1
python-Pillow - addressed in versions 4.2.1-3.23.2, 5.2.0-3.20.1
python-Pillow-debugsource - addressed in versions 4.2.1-3.23.2, 5.2.0-3.20.1, 7.2.0-150300.3.3.1, 9.5.0-150400.5.6.1
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.2
python3-pillow - addressed in versions 5.1.1-20, 10.1.0-1
python3-pillow-devel - addressed in versions 5.1.1-20, 10.1.0-1
python3-pillow-tk - addressed in versions 5.1.1-20, 10.1.0-1
python3-pillow-doc - addressed in versions 5.1.1-20, 10.1.0-1
XtremIO X2 - update to 6.4.2-13
python3-pil (Ubuntu package) - addressed in versions 7.0.0-4ubuntu0.8, 9.0.1-1ubuntu0.2, 10.0.0-1ubuntu0.1
python3-Pillow-tk-debuginfo - update to 7.2.0-150300.3.3.1
python3-Pillow-tk - update to 7.2.0-150300.3.3.1
python3-Pillow - update to 7.2.0-150300.3.3.1
python3-Pillow-debuginfo - update to 7.2.0-150300.3.3.1
pillow (Debian package) - addressed in versions 8.1.2+dfsg-0.3+deb11u2, 9.4.0-1.1+deb12u1
python3-pillow-tk - update to 9.0.1-3
python3-pillow - update to 9.0.1-3
python-pillow-debuginfo - update to 9.0.1-3
python3-pillow-devel - update to 9.0.1-3
python3-pillow-help - update to 9.0.1-3
python3-pillow-qt - update to 9.0.1-3
python-pillow-debugsource - update to 9.0.1-3
python-pillow - update to 9.0.1-3
python-pillow - update to 9.4.0-2
python-pillow - addressed in versions 9.5.0-1.fc38, 9.5.0-2.fc38, 9.5.0-3.fc38
python311-Pillow-tk - update to 9.5.0-150400.5.6.1
python311-Pillow-tk-debuginfo - update to 9.5.0-150400.5.6.1
python311-Pillow - update to 9.5.0-150400.5.6.1
python311-Pillow-debuginfo - update to 9.5.0-150400.5.6.1
python3-pillow-qt - update to 10.1.0-1
dev-python/pillow - update to 10.2.0
IBM Business Automation Workflow - update to 23.0.2 IF001
Maximo Application Suite - Edge Data Collector - update to 8.11.3
python-pillow - update to 2.0.0-24.gitd1c6db8
python-pillow-devel - update to 2.0.0-24.gitd1c6db8
python-pillow-doc - update to 2.0.0-24.gitd1c6db8
python-pillow-tk - update to 2.0.0-24.gitd1c6db8
python-pillow-sane - update to 2.0.0-24.gitd1c6db8
python-pillow-qt - update to 2.0.0-24.gitd1c6db8
python-pillow (Red Hat package) - addressed in versions 2.0.0-24.gitd1c6db8.el7_9, 5.1.1-20.el8
Cloud Pak for Network Automation - update to 2.6.4
python-Pillow-debuginfo - addressed in versions 4.2.1-3.23.2, 5.2.0-3.20.1, 7.2.0-150300.3.3.1, 9.5.0-150400.5.6.1
python-Pillow - addressed in versions 4.2.1-3.23.2, 5.2.0-3.20.1
python-Pillow-debugsource - addressed in versions 4.2.1-3.23.2, 5.2.0-3.20.1, 7.2.0-150300.3.3.1, 9.5.0-150400.5.6.1
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.2
python3-pillow - addressed in versions 5.1.1-20, 10.1.0-1
python3-pillow-devel - addressed in versions 5.1.1-20, 10.1.0-1
python3-pillow-tk - addressed in versions 5.1.1-20, 10.1.0-1
python3-pillow-doc - addressed in versions 5.1.1-20, 10.1.0-1
XtremIO X2 - update to 6.4.2-13
python3-pil (Ubuntu package) - addressed in versions 7.0.0-4ubuntu0.8, 9.0.1-1ubuntu0.2, 10.0.0-1ubuntu0.1
python3-Pillow-tk-debuginfo - update to 7.2.0-150300.3.3.1
python3-Pillow-tk - update to 7.2.0-150300.3.3.1
python3-Pillow - update to 7.2.0-150300.3.3.1
python3-Pillow-debuginfo - update to 7.2.0-150300.3.3.1
pillow (Debian package) - addressed in versions 8.1.2+dfsg-0.3+deb11u2, 9.4.0-1.1+deb12u1
python3-pillow-tk - update to 9.0.1-3
python3-pillow - update to 9.0.1-3
python-pillow-debuginfo - update to 9.0.1-3
python3-pillow-devel - update to 9.0.1-3
python3-pillow-help - update to 9.0.1-3
python3-pillow-qt - update to 9.0.1-3
python-pillow-debugsource - update to 9.0.1-3
python-pillow - update to 9.0.1-3
python-pillow - update to 9.4.0-2
python-pillow - addressed in versions 9.5.0-1.fc38, 9.5.0-2.fc38, 9.5.0-3.fc38
python311-Pillow-tk - update to 9.5.0-150400.5.6.1
python311-Pillow-tk-debuginfo - update to 9.5.0-150400.5.6.1
python311-Pillow - update to 9.5.0-150400.5.6.1
python311-Pillow-debuginfo - update to 9.5.0-150400.5.6.1
python3-pillow-qt - update to 10.1.0-1
dev-python/pillow - update to 10.2.0
IBM Business Automation Workflow - update to 23.0.2 IF001
External References
- https://devhub.checkmarx.com/cve-details/CVE-2023-44271/
- https://github.com/python-pillow/Pillow/pull/7244
- https://github.com/python-pillow/Pillow/commit/1fe1bb49c452b0318cad12ea9d97c3bef188e9a7
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N2JOEDUJDQLCUII2LQYZYSM7RJL2I3P4/
Related Security Bulletins
- Denial of service in Pillow
- SUSE update for python-Pillow
- Fedora 38 update for python-pillow
- Fedora 38 update for python-pillow
- SUSE update for python-Pillow
- SUSE update for python-Pillow
- SUSE update for python-Pillow
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Red Hat Enterprise Linux 7 update for python-pillow
- CentOS 7 update for python-pillow
- Fedora 38 update for python-pillow
- Ubuntu update for pillow
- Resource exhaustion in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4 for RHEL 9
- Resource exhaustion in IBM Edge Data Collector
- openEuler update for python-pillow
- Multiple vulnerabilities in Oracle Banking Origination
- Multiple vulnerabilities in Oracle Banking Liquidity Management
- Red Hat Enterprise Linux 8 update for python-pillow
- Gentoo update for Pillow
- Debian update for pillow
- Multiple vulnerabilities in IBM PowerVC
- Multiple vulnerabilities in Dell XtremIO X2
- Amazon Linux AMI update for python-pillow
- Anolis OS update for python-pillow
- Anolis OS update for python-pillow
- Anolis OS update for python-pillow