Skip to content

RFC: Decompression bomb error - #2583

Merged
wiredfool merged 2 commits into
python-pillow:masterfrom
wiredfool:decompression_bomb_error
Dec 20, 2017
Merged

wiredfool merged 2 commits into
python-pillow:masterfrom
wiredfool:decompression_bomb_error

Conversation

@wiredfool

@wiredfool wiredfool commented Jun 21, 2017 •

Copy link
Copy Markdown
Member

Noted in #2410.

Changes proposed in this pull request:

  • Added a DecompressionBombError for if the requested size is 2*Image.MAX_PIXELS

Note that this will cause new exceptions, so we should make sure we really want to do this.

@wiredfool
wiredfool force-pushed the decompression_bomb_error branch from 7f6fa3a to e47b0fc Compare June 21, 2017 09:55
@wiredfool wiredfool changed the title Decompression bomb error RFC: Decompression bomb error Jun 21, 2017
@wiredfool
wiredfool force-pushed the decompression_bomb_error branch from e47b0fc to 1a1a2ed Compare June 21, 2017 10:55

@hugovk hugovk left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems reasonable, 2 * Image.MAX_IMAGE_PIXELS is half a gigabyte for a 24 bit (3 bpp) image.

People needing to work with such big images need to explicitly reset Image.MAX_IMAGE_PIXELS to something suitable for themselves.

Is it worthwhile having two constants to allow users to adjust both according to their needs?

@wiredfool

Copy link
Copy Markdown
Member Author

#2832 need release notes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants