cbcvebase.

Debian Pillow vulnerabilities

54 known vulnerabilities affecting debian/pillow.

Total CVEs
54
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH20MEDIUM17LOW9

Vulnerabilities

Page 2 of 3
CVE-2021-27922P3HIGHCVSS 7.5fixed in pillow 8.1.2-1 (bookworm)2021
CVE-2021-27922 [HIGH] CVE-2021-27922: pillow - Pillow before 8.1.2 allows attackers to cause a denial of service (memory consum... Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large. Scope: local bookworm: resolved (fixed in 8.1.2-1) bullseye: resolved (fixed in 8.1.2-1) forky: resolved (fixed in 8.1.2-1) sid:
debian
CVE-2021-23437P3HIGHCVSS 7.5fixed in pillow 8.3.2-1 (bookworm)2021
CVE-2021-23437 [HIGH] CVE-2021-23437: pillow - The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression D... The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function. Scope: local bookworm: resolved (fixed in 8.3.2-1) bullseye: resolved (fixed in 8.1.2+dfsg-0.3+deb11u3) forky: resolved (fixed in 8.3.2-1) sid: resolved (fixed in 8.3.2-1) trixie: resolved (fixed in 8.3.2-1)
debian
CVE-2021-25293P3HIGHCVSS 7.5fixed in pillow 8.1.1-1 (bookworm)2021
CVE-2021-25293 [HIGH] CVE-2021-25293: pillow - An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read i... An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c. Scope: local bookworm: resolved (fixed in 8.1.1-1) bullseye: resolved (fixed in 8.1.1-1) forky: resolved (fixed in 8.1.1-1) sid: resolved (fixed in 8.1.1-1) trixie: resolved (fixed in 8.1.1-1)
debian
CVE-2022-45198P3HIGHCVSS 7.5fixed in pillow 9.2.0-1 (bookworm)2022
CVE-2022-45198 [HIGH] CVE-2022-45198: pillow - Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Da... Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification). Scope: local bookworm: resolved (fixed in 9.2.0-1) bullseye: resolved (fixed in 8.1.2+dfsg-0.3+deb11u3) forky: resolved (fixed in 9.2.0-1) sid: resolved (fixed in 9.2.0-1) trixie: resolved (fixed in 9.2.0-1)
debian
CVE-2021-27921P3HIGHCVSS 7.5fixed in pillow 8.1.2-1 (bookworm)2021
CVE-2021-27921 [HIGH] CVE-2021-27921: pillow - Pillow before 8.1.2 allows attackers to cause a denial of service (memory consum... Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large. Scope: local bookworm: resolved (fixed in 8.1.2-1) bullseye: resolved (fixed in 8.1.2-1) forky: resolved (fixed in 8.1.2-1) sid: re
debian
CVE-2021-27923P3HIGHCVSS 7.5fixed in pillow 8.1.2-1 (bookworm)2021
CVE-2021-27923 [HIGH] CVE-2021-27923: pillow - Pillow before 8.1.2 allows attackers to cause a denial of service (memory consum... Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large. Scope: local bookworm: resolved (fixed in 8.1.2-1) bullseye: resolved (fixed in 8.1.2-1) forky: resolved (fixed in 8.1.2-1) sid: r
debian
CVE-2021-25290P3HIGHCVSS 7.5fixed in pillow 8.1.1-1 (bookworm)2021
CVE-2021-25290 [HIGH] CVE-2021-25290: pillow - An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a nega... An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size. Scope: local bookworm: resolved (fixed in 8.1.1-1) bullseye: resolved (fixed in 8.1.1-1) forky: resolved (fixed in 8.1.1-1) sid: resolved (fixed in 8.1.1-1) trixie: resolved (fixed in 8.1.1-1)
debian
CVE-2019-19911P3HIGHCVSS 7.5fixed in pillow 7.0.0-1 (bookworm)2019
CVE-2019-19911 [HIGH] CVE-2019-19911: pillow - There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py ... There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the
debian
CVE-2021-25291P4HIGHCVSS 7.5fixed in pillow 8.1.1-1 (bookworm)2021
CVE-2021-25291 [HIGH] CVE-2021-25291: pillow - An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out... An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries. Scope: local bookworm: resolved (fixed in 8.1.1-1) bullseye: resolved (fixed in 8.1.1-1) forky: resolved (fixed in 8.1.1-1) sid: resolved (fixed in 8.1.1-1) trixie: resolved (fixed in 8.1.1-1)
debian
CVE-2023-44271P4HIGHCVSS 7.5fixed in pillow 9.4.0-1.1+deb12u1 (bookworm)2023
CVE-2023-44271 [HIGH] CVE-2023-44271: pillow - An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that ... An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument. Scope: local bookworm: resolved (fixed in 9.4.0-
debian
CVE-2020-10379P4HIGHCVSS 7.8fixed in pillow 7.2.0-1 (bookworm)2020
CVE-2020-10379 [HIGH] CVE-2020-10379: pillow - In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.... In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c. Scope: local bookworm: resolved (fixed in 7.2.0-1) bullseye: resolved (fixed in 7.2.0-1) forky: resolved (fixed in 7.2.0-1) sid: resolved (fixed in 7.2.0-1) trixie: resolved (fixed in 7.2.0-1)
debian
CVE-2020-5313P4HIGHCVSS 7.1fixed in pillow 7.0.0-1 (bookworm)2020
CVE-2020-5313 [HIGH] CVE-2020-5313: pillow - libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow. libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow. Scope: local bookworm: resolved (fixed in 7.0.0-1) bullseye: resolved (fixed in 7.0.0-1) forky: resolved (fixed in 7.0.0-1) sid: resolved (fixed in 7.0.0-1) trixie: resolved (fixed in 7.0.0-1)
debian
CVE-2022-45199P4HIGHCVSS 7.5fixed in pillow 9.3.0-1 (bookworm)2022
CVE-2022-45199 [HIGH] CVE-2022-45199: pillow - Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL. Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL. Scope: local bookworm: resolved (fixed in 9.3.0-1) bullseye: resolved forky: resolved (fixed in 9.3.0-1) sid: resolved (fixed in 9.3.0-1) trixie: resolved (fixed in 9.3.0-1)
debian
CVE-2016-0740P4MEDIUMCVSS 6.5fixed in pillow 3.1.1-1 (bookworm)2016
CVE-2016-0740 [MEDIUM] CVE-2016-0740: pillow - Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c ... Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file. Scope: local bookworm: resolved (fixed in 3.1.1-1) bullseye: resolved (fixed in 3.1.1-1) forky: resolved (fixed in 3.1.1-1) sid: resolved (fixed in 3.1.1-1) trixie: resolved (fixed in 3.1.1-1)
debian
CVE-2022-22816P4MEDIUMCVSS 6.5fixed in pillow 9.0.0-1 (bookworm)2022
CVE-2022-22816 [MEDIUM] CVE-2022-22816: pillow - path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during init... path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path. Scope: local bookworm: resolved (fixed in 9.0.0-1) bullseye: resolved (fixed in 8.1.2+dfsg-0.3+deb11u1) forky: resolved (fixed in 9.0.0-1) sid: resolved (fixed in 9.0.0-1) trixie: resolved (fixed in 9.0.0-1)
debian
CVE-2020-35653P4HIGHCVSS 7.1fixed in pillow 8.1.0-1 (bookworm)2020
CVE-2020-35653 [HIGH] CVE-2020-35653: pillow - In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted... In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations. Scope: local bookworm: resolved (fixed in 8.1.0-1) bullseye: resolved (fixed in 8.1.0-1) forky: resolved (fixed in 8.1.0-1) sid: resolved (fixed in 8.1.0-1) trixie: resolved (fixed in 8.1.0-1)
debian
CVE-2022-22815P4MEDIUMCVSS 6.5fixed in pillow 9.0.0-1 (bookworm)2022
CVE-2022-22815 [MEDIUM] CVE-2022-22815: pillow - path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.P... path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path. Scope: local bookworm: resolved (fixed in 9.0.0-1) bullseye: resolved (fixed in 8.1.2+dfsg-0.3+deb11u1) forky: resolved (fixed in 9.0.0-1) sid: resolved (fixed in 9.0.0-1) trixie: resolved (fixed in 9.0.0-1)
debian
CVE-2024-28219P4MEDIUMCVSS 6.7fixed in pillow 9.4.0-1.1+deb12u1 (bookworm)2024
CVE-2024-28219 [MEDIUM] CVE-2024-28219: pillow - In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcp... In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy. Scope: local bookworm: resolved (fixed in 9.4.0-1.1+deb12u1) bullseye: resolved (fixed in 8.1.2+dfsg-0.3+deb11u2) forky: resolved (fixed in 10.3.0-1) sid: resolved (fixed in 10.3.0-1) trixie: resolved (fixed in 10.3.0-1)
debian
CVE-2016-2533P4MEDIUMCVSS 6.5fixed in pillow 3.1.1-1 (bookworm)2016
CVE-2016-2533 [MEDIUM] CVE-2016-2533: pillow - Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before... Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file. Scope: local bookworm: resolved (fixed in 3.1.1-1) bullseye: resolved (fixed in 3.1.1-1) forky: resolved (fixed in 3.1.1-1) sid: resolved (fix
debian
CVE-2021-25292P4MEDIUMCVSS 6.5fixed in pillow 8.1.1-1 (bookworm)2021
CVE-2021-25292 [MEDIUM] CVE-2021-25292: pillow - An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular ... An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a crafted PDF file because of a catastrophic backtracking regex. Scope: local bookworm: resolved (fixed in 8.1.1-1) bullseye: resolved (fixed in 8.1.1-1) forky: resolved (fixed in 8.1.1-1) sid: resolved (fixed in 8.1.1-1) trixie: resolved (fixed in 8.1.
debian
Debian Pillow vulnerabilities | cvebase