cbcvebase.

Debian Pillow vulnerabilities

54 known vulnerabilities affecting debian/pillow.

Total CVEs
54
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH20MEDIUM17LOW9

Vulnerabilities

Page 1 of 3
CVE-2014-3007P3MEDIUMCVSS 4.4fixed in pillow 2.4.0-1 (bookworm)2014
CVE-2014-3007 [MEDIUM] CVE-2014-3007: pillow - Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote a... Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py. Scope: local bookworm: resolved (fixed in 2.4.0-1) bullseye: resolved (fixed in 2.4.0-1) forky: resolved (fixed in 2.4.0-1) sid: resolved (fixed in
debian
CVE-2022-22817P3CRITICALCVSS 9.8fixed in pillow 9.0.0-1 (bookworm)2022
CVE-2022-22817 [CRITICAL] CVE-2022-22817: pillow - PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary express... PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used. Scope: local bookworm: resolved (fixed in 9.0.0-1) bullseye: resolved (fixed in 8.1.2+dfsg-0.3+deb11u1) forky: resolved (fixed in 9.0.0-1) sid: resolved (fixed in 9.0.0-1) trixie: resolved (fix
debian
CVE-2021-34552P3CRITICALCVSS 9.8fixed in pillow 8.1.2+dfsg-0.3 (bookworm)2021
CVE-2021-34552 [CRITICAL] CVE-2021-34552: pillow - Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an... Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c. Scope: local bookworm: resolved (fixed in 8.1.2+dfsg-0.3) bullseye: resolved (fixed in 8.1.2+dfsg-0.3) forky: resolved (fixed in 8.1.2+dfsg-0.3) sid: resolved (fixed in
debian
CVE-2016-4009P3CRITICALCVSS 9.8fixed in pillow 3.1.1-1 (bookworm)2016
CVE-2016-4009 [CRITICAL] CVE-2016-4009: pillow - Integer overflow in the ImagingResampleHorizontal function in libImaging/Resampl... Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 3.1.1-1) bullseye: resolved (fixed in 3.1.1-1) forky: resolved (fixed in 3.1.1-1) sid
debian
CVE-2022-30595P3CRITICALCVSS 9.8fixed in pillow 9.1.1-1 (bookworm)2022
CVE-2022-30595 [CRITICAL] CVE-2022-30595: pillow - libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the proc... libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files. Scope: local bookworm: resolved (fixed in 9.1.1-1) bullseye: resolved forky: resolved (fixed in 9.1.1-1) sid: resolved (fixed in 9.1.1-1) trixie: resolved (fixed in 9.1.1-1)
debian
CVE-2020-5312P3CRITICALCVSS 9.8fixed in pillow 7.0.0-1 (bookworm)2020
CVE-2020-5312 [CRITICAL] CVE-2020-5312: pillow - libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow. libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow. Scope: local bookworm: resolved (fixed in 7.0.0-1) bullseye: resolved (fixed in 7.0.0-1) forky: resolved (fixed in 7.0.0-1) sid: resolved (fixed in 7.0.0-1) trixie: resolved (fixed in 7.0.0-1)
debian
CVE-2023-50447P3CRITICALCVSS 9.8fixed in pillow 9.4.0-1.1+deb12u1 (bookworm)2023
CVE-2023-50447 [CRITICAL] CVE-2023-50447: pillow - Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the... Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter). Scope: local bookworm: resolved (fixed in 9.4.0-1.1+deb12u1) bullseye: resolved (fixed in 8.1.2+dfsg-0.3+deb11u2) forky: resolved (fixed in 10.2.0-1) sid: resolved (fixed
debian
CVE-2020-5311P3CRITICALCVSS 9.8fixed in pillow 7.0.0-1 (bookworm)2020
CVE-2020-5311 [CRITICAL] CVE-2020-5311: pillow - libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow. libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow. Scope: local bookworm: resolved (fixed in 7.0.0-1) bullseye: resolved (fixed in 7.0.0-1) forky: resolved (fixed in 7.0.0-1) sid: resolved (fixed in 7.0.0-1) trixie: resolved (fixed in 7.0.0-1)
debian
CVE-2022-24303P3CRITICALCVSS 9.1fixed in pillow 9.0.1-1 (bookworm)2022
CVE-2022-24303 [CRITICAL] CVE-2022-24303: pillow - Pillow before 9.0.1 allows attackers to delete files because spaces in temporary... Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled. Scope: local bookworm: resolved (fixed in 9.0.1-1) bullseye: resolved (fixed in 8.1.2+dfsg-0.3+deb11u3) forky: resolved (fixed in 9.0.1-1) sid: resolved (fixed in 9.0.1-1) trixie: resolved (fixed in 9.0.1-1)
debian
CVE-2021-25289P3HIGHCVSS 8.8fixed in pillow 8.1.1-1 (bookworm)2021
CVE-2021-25289 [HIGH] CVE-2021-25289: pillow - An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buff... An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for CVE-2020-35654. Scope: local bookworm: resolved (fixed in 8.1.1-1) bullseye: resolved (fixed in 8.1.1-1) forky: res
debian
CVE-2020-35654P3HIGHCVSS 8.8fixed in pillow 8.1.0-1 (bookworm)2020
CVE-2020-35654 [HIGH] CVE-2020-35654: pillow - In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decodin... In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. Scope: local bookworm: resolved (fixed in 8.1.0-1) bullseye: resolved (fixed in 8.1.0-1) forky: resolved (fixed in 8.1.0-1) sid: resolved (fixed in 8.1.0-1) trixie: resolved (fixed in 8.1.0-1)
debian
CVE-2021-25287P3LOWCVSS 9.1fixed in pillow 8.1.2+dfsg-0.2 (bookworm)2021
CVE-2021-25287 [CRITICAL] CVE-2021-25287: pillow - An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read i... An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la. Scope: local bookworm: resolved (fixed in 8.1.2+dfsg-0.2) bullseye: resolved (fixed in 8.1.2+dfsg-0.2) forky: resolved (fixed in 8.1.2+dfsg-0.2) sid: resolved (fixed in 8.1.2+dfsg-0.2) trixie: resolved (fixed in 8.1.2+dfsg-0.2)
debian
CVE-2026-25990P3LOWCVSS 8.9fixed in pillow 12.1.1-1 (forky)2026
CVE-2026-25990 [HIGH] CVE-2026-25990: pillow - Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, n out-of-bound... Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, n out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 12.1.1-1) sid: resolved (fixed in 12.1.1-1) trixie: resolved (fixed in 11.1.0-5+deb13u1)
debian
CVE-2021-25288P3LOWCVSS 9.1fixed in pillow 8.1.2+dfsg-0.2 (bookworm)2021
CVE-2021-25288 [CRITICAL] CVE-2021-25288: pillow - An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read i... An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i. Scope: local bookworm: resolved (fixed in 8.1.2+dfsg-0.2) bullseye: resolved (fixed in 8.1.2+dfsg-0.2) forky: resolved (fixed in 8.1.2+dfsg-0.2) sid: resolved (fixed in 8.1.2+dfsg-0.2) trixie: resolved (fixed in 8.1.2+dfsg-0.2)
debian
CVE-2020-11538P3LOWCVSS 8.1fixed in pillow 7.2.0-1 (bookworm)2020
CVE-2020-11538 [HIGH] CVE-2020-11538: pillow - In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds ... In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311. Scope: local bookworm: resolved (fixed in 7.2.0-1) bullseye: resolved (fixed in 7.2.0-1) forky: resolved (fixed in 7.2.0-1) sid: resolved (fixed in 7.2.0-1) trixie: resolved (fixed in 7.2.0-1)
debian
CVE-2020-5310P3HIGHCVSS 8.8fixed in pillow 7.0.0-1 (bookworm)2020
CVE-2020-5310 [HIGH] CVE-2020-5310: pillow - libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overf... libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc. Scope: local bookworm: resolved (fixed in 7.0.0-1) bullseye: resolved (fixed in 7.0.0-1) forky: resolved (fixed in 7.0.0-1) sid: resolved (fixed in 7.0.0-1) trixie: resolved (fixed in 7.0.0-1)
debian
CVE-2019-16865P3LOWCVSS 7.5fixed in pillow 6.2.0-1 (bookworm)2019
CVE-2019-16865 [HIGH] CVE-2019-16865: pillow - An issue was discovered in Pillow before 6.2.0. When reading specially crafted i... An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image. Scope: local bookworm: resolved (fixed in 6.2.0-1) bullseye: resolved (fixed in 6.2.0-1) forky: resolved (fixed in 6.2.0-1) sid: resolved (fixed
debian
CVE-2016-9190P3HIGHCVSS 7.8fixed in pillow 3.4.2-1 (bookworm)2016
CVE-2016-9190 [HIGH] CVE-2016-9190: pillow - Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code... Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component. Scope: local bookworm: resolved (fixed in 3.4.2-1) bullseye: resolved (fixed in 3.4.2-1) forky: resolved (fixed in 3.4.2-1) sid: resolved (fixed in 3.4
debian
CVE-2021-28677P3HIGHCVSS 7.5fixed in pillow 8.1.2+dfsg-0.2 (bookworm)2021
CVE-2021-28677 [HIGH] CVE-2021-28677: pillow - An issue was discovered in Pillow before 8.2.0. For EPS data, the readline imple... An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image w
debian
CVE-2021-28676P3HIGHCVSS 7.5fixed in pillow 8.1.2+dfsg-0.2 (bookworm)2021
CVE-2021-28676 [HIGH] CVE-2021-28676: pillow - An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not ... An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load. Scope: local bookworm: resolved (fixed in 8.1.2+dfsg-0.2) bullseye: resolved (fixed in 8.1.2+dfsg-0.2) forky: resolved (fixed in 8.1.2+dfsg-0.2) sid: resolved (fixed in 8.1.2+dfsg-0.2) tri
debian
Debian Pillow vulnerabilities | cvebase