Debian DLA-2057-1 : pillow security update

high Nessus Plugin ID 132681

Synopsis

The remote Debian host is missing a security update.

Description

It was discovered that there were three vulnerabilities in Pillow, an imaging library for the Python programming language :

- CVE-2019-19911: Prevent a denial of service vulnerability caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large.

- CVE-2020-5312: PCX 'P mode' buffer overflow.

- CVE-2020-5313: FLI buffer overflow.

For Debian 8 'Jessie', these issues have been fixed in pillow version 2.6.1-2+deb8u4.

We recommend that you upgrade your pillow packages.

NOTE: Tenable Network Security has extracted the preceding description block directly from the DLA security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Upgrade the affected packages.

See Also

https://lists.debian.org/debian-lts-announce/2020/01/msg00003.html

https://packages.debian.org/source/jessie/pillow

Plugin Details

Severity: High

ID: 132681

File Name: debian_DLA-2057.nasl

Version: 1.3

Type: local

Agent: unix

Published: 1/7/2020

Updated: 1/11/2021

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:python-imaging, p-cpe:/a:debian:debian_linux:python-pil.imagetk, p-cpe:/a:debian:debian_linux:python3-sane-dbg, p-cpe:/a:debian:debian_linux:python-sane, p-cpe:/a:debian:debian_linux:python-pil.imagetk-dbg, p-cpe:/a:debian:debian_linux:python3-pil.imagetk-dbg, p-cpe:/a:debian:debian_linux:python-imaging-tk, p-cpe:/a:debian:debian_linux:python3-sane, p-cpe:/a:debian:debian_linux:python-pil, p-cpe:/a:debian:debian_linux:python-sane-dbg, p-cpe:/a:debian:debian_linux:python3-pil.imagetk, p-cpe:/a:debian:debian_linux:python-pil-doc, cpe:/o:debian:debian_linux:8.0, p-cpe:/a:debian:debian_linux:python-pil-dbg, p-cpe:/a:debian:debian_linux:python3-pil-dbg, p-cpe:/a:debian:debian_linux:python3-pil

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 1/6/2020

Vulnerability Publication Date: 1/6/2020