Pillow release 2.7.0 fixes a potential denial-of-service issue in PNG decompression code [1]. Exact upstream commit that resolves this: https://github.com/python-pillow/Pillow/commit/b3e09122e527ae554eb590741bbd7611d5710e40 [1]: http://pillow.readthedocs.org/releasenotes/2.7.0.html#png-text-chunk-size-limits
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-9601 to the following vulnerability: Name: CVE-2014-9601 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9601 Assigned: 20150116 Reference: https://www.djangoproject.com/weblog/2015/jan/02/pillow-security-release/ Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.