VDB
KO

PYSEC-2023-227

Details

An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / pillow
Introduced in: 0 Fixed in: 1fe1bb49c452b0318cad12ea9d97c3bef188e9a7
Fix pip install --upgrade 'pillow>=1fe1bb49c452b0318cad12ea9d97c3bef188e9a7'

References