{
  "threat_severity" : "Moderate",
  "public_date" : "2020-01-03T00:00:00Z",
  "bugzilla" : {
    "description" : "python-pillow: uncontrolled resource consumption in FpxImagePlugin.py",
    "id" : "1789540",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1789540"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-400",
  "details" : [ "There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.", "A denial of service vulnerability was found in Pillow in versions before 6.2.2, where the FpxImagePlugin.py file calls the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows systems running 32-bit Python, this flaw results in an OverflowError or MemoryError due to the 2 GB limit. On Linux systems running 64-bit Python, this flaw results in the termination of the process by the out-of-memory (OOM) killer. The highest threat from this vulnerability is to system availability." ],
  "statement" : "This issue did not affect the versions of python-pillow as shipped with Red Hat Enterprise Linux 7, and 8 as they did not include python-olefile, which is necessary to use the FPX image plugin.",
  "affected_release" : [ {
    "product_name" : "Red Hat Quay 3",
    "release_date" : "2021-02-04T00:00:00Z",
    "advisory" : "RHSA-2021:0420",
    "cpe" : "cpe:/a:redhat:quay:3::el8",
    "package" : "quay/clair-rhel8:v3.4.0-25"
  }, {
    "product_name" : "Red Hat Quay 3",
    "release_date" : "2021-02-04T00:00:00Z",
    "advisory" : "RHSA-2021:0420",
    "cpe" : "cpe:/a:redhat:quay:3::el8",
    "package" : "quay/quay-bridge-operator-bundle:v3.4.0-3"
  }, {
    "product_name" : "Red Hat Quay 3",
    "release_date" : "2021-02-04T00:00:00Z",
    "advisory" : "RHSA-2021:0420",
    "cpe" : "cpe:/a:redhat:quay:3::el8",
    "package" : "quay/quay-bridge-operator-rhel8:v3.4.0-17"
  }, {
    "product_name" : "Red Hat Quay 3",
    "release_date" : "2021-02-04T00:00:00Z",
    "advisory" : "RHSA-2021:0420",
    "cpe" : "cpe:/a:redhat:quay:3::el8",
    "package" : "quay/quay-builder-qemu-rhcos-rhel8:v3.4.0-17"
  }, {
    "product_name" : "Red Hat Quay 3",
    "release_date" : "2021-02-04T00:00:00Z",
    "advisory" : "RHSA-2021:0420",
    "cpe" : "cpe:/a:redhat:quay:3::el8",
    "package" : "quay/quay-builder-rhel8:v3.4.0-18"
  }, {
    "product_name" : "Red Hat Quay 3",
    "release_date" : "2021-02-04T00:00:00Z",
    "advisory" : "RHSA-2021:0420",
    "cpe" : "cpe:/a:redhat:quay:3::el8",
    "package" : "quay/quay-container-security-operator-bundle:v3.4.0-2"
  }, {
    "product_name" : "Red Hat Quay 3",
    "release_date" : "2021-02-04T00:00:00Z",
    "advisory" : "RHSA-2021:0420",
    "cpe" : "cpe:/a:redhat:quay:3::el8",
    "package" : "quay/quay-container-security-operator-rhel8:v3.4.0-2"
  }, {
    "product_name" : "Red Hat Quay 3",
    "release_date" : "2021-02-04T00:00:00Z",
    "advisory" : "RHSA-2021:0420",
    "cpe" : "cpe:/a:redhat:quay:3::el8",
    "package" : "quay/quay-openshift-bridge-rhel8-operator:v3.4.0-17"
  }, {
    "product_name" : "Red Hat Quay 3",
    "release_date" : "2021-02-04T00:00:00Z",
    "advisory" : "RHSA-2021:0420",
    "cpe" : "cpe:/a:redhat:quay:3::el8",
    "package" : "quay/quay-operator-bundle:v3.4.0-89"
  }, {
    "product_name" : "Red Hat Quay 3",
    "release_date" : "2021-02-04T00:00:00Z",
    "advisory" : "RHSA-2021:0420",
    "cpe" : "cpe:/a:redhat:quay:3::el8",
    "package" : "quay/quay-operator-rhel8:v3.4.0-132"
  }, {
    "product_name" : "Red Hat Quay 3",
    "release_date" : "2021-02-04T00:00:00Z",
    "advisory" : "RHSA-2021:0420",
    "cpe" : "cpe:/a:redhat:quay:3::el8",
    "package" : "quay/quay-rhel8:v3.4.0-51"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Out of support scope",
    "package_name" : "python-imaging",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "python-imaging",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "python-pillow",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "python-pillow",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2019-19911\nhttps://nvd.nist.gov/vuln/detail/CVE-2019-19911" ],
  "name" : "CVE-2019-19911",
  "csaw" : false
}