Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
{
"github_reviewed": true,
"cwe_ids": [
"CWE-20"
],
"github_reviewed_at": "2023-08-16T22:08:45Z",
"nvd_published_at": "2015-01-16T16:59:00Z",
"severity": "HIGH"
}