Debian Pillow vulnerabilities
54 known vulnerabilities affecting debian/pillow.
Total CVEs
54
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH20MEDIUM17LOW9
Vulnerabilities
Page 3 of 3
CVE-2016-0775P4MEDIUMCVSS 6.5fixed in pillow 3.1.1-1 (bookworm)2016
CVE-2016-0775 [MEDIUM] CVE-2016-0775: pillow - Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pi...
Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.
Scope: local
bookworm: resolved (fixed in 3.1.1-1)
bullseye: resolved (fixed in 3.1.1-1)
forky: resolved (fixed in 3.1.1-1)
sid: resolved (fixed in 3.1.1-1)
trixie: resolved (fixed in 3.
debian
CVE-2020-35655P4MEDIUMCVSS 5.4fixed in pillow 8.1.0-1 (bookworm)2020
CVE-2020-35655 [MEDIUM] CVE-2020-35655: pillow - In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding...
In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.
Scope: local
bookworm: resolved (fixed in 8.1.0-1)
bullseye: resolved (fixed in 8.1.0-1)
forky: resolved (fixed in 8.1.0-1)
sid: resolved (fixed in 8.1.0-1)
trixie: resolved (fixed in 8.1.0-1)
debian
CVE-2016-3076P4LOWCVSS 5.5fixed in pillow 3.2.0-1 (bookworm)2016
CVE-2016-3076 [MEDIUM] CVE-2016-3076: pillow - Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 thro...
Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.
Scope: local
bookworm: resolved (fixed in 3.2.0-1)
bullseye: resolved (fixed in 3.2.0-1)
forky: resolved (fixed in 3.2.0-1)
sid: resolved (fixed in 3.2.0-1)
trixie: resolved (fi
debian
CVE-2016-9189P4MEDIUMCVSS 5.5fixed in pillow 3.4.2-1 (bookworm)2016
CVE-2016-9189 [MEDIUM] CVE-2016-9189: pillow - Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive infor...
Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.
Scope: local
bookworm: resolved (fixed in 3.4.2-1)
bullseye: resolved (fixed in 3.4.2-1)
forky: resolved (fixed in 3.4.2-1)
sid: resolved (fixe
debian
CVE-2014-9601P4MEDIUMCVSS 5.0fixed in pillow 2.6.1-2 (bookworm)2014
CVE-2014-9601 [MEDIUM] CVE-2014-9601: pillow - Pillow before 2.7.0 allows remote attackers to cause a denial of service via a c...
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
Scope: local
bookworm: resolved (fixed in 2.6.1-2)
bullseye: resolved (fixed in 2.6.1-2)
forky: resolved (fixed in 2.6.1-2)
sid: resolved (fixed in 2.6.1-2)
trixie: resolved (fixed in 2.6.1-2)
debian
CVE-2014-3598P4MEDIUMCVSS 5.0fixed in pillow 2.5.3-1 (bookworm)2014
CVE-2014-3598 [MEDIUM] CVE-2014-3598: pillow - The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to c...
The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image.
Scope: local
bookworm: resolved (fixed in 2.5.3-1)
bullseye: resolved (fixed in 2.5.3-1)
forky: resolved (fixed in 2.5.3-1)
sid: resolved (fixed in 2.5.3-1)
trixie: resolved (fixed in 2.5.3-1)
debian
CVE-2014-3589P4MEDIUMCVSS 5.0fixed in pillow 2.5.3-1 (bookworm)2014
CVE-2014-3589 [MEDIUM] CVE-2014-3589: pillow - PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 a...
PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.
Scope: local
bookworm: resolved (fixed in 2.5.3-1)
bullseye: resolved (fixed in 2.5.3-1)
forky: resolved (fixed in 2.5.3-1)
sid: resolved (fixed in 2.5.3-1)
trixie: resolved (fixed in 2.5.
debian
CVE-2020-10177P4MEDIUMCVSS 5.5fixed in pillow 7.2.0-1 (bookworm)2020
CVE-2020-10177 [MEDIUM] CVE-2020-10177: pillow - Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.
Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.
Scope: local
bookworm: resolved (fixed in 7.2.0-1)
bullseye: resolved (fixed in 7.2.0-1)
forky: resolved (fixed in 7.2.0-1)
sid: resolved (fixed in 7.2.0-1)
trixie: resolved (fixed in 7.2.0-1)
debian
CVE-2020-10378P4MEDIUMCVSS 5.5fixed in pillow 7.2.0-1 (bookworm)2020
CVE-2020-10378 [MEDIUM] CVE-2020-10378: pillow - In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occu...
In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.
Scope: local
bookworm: resolved (fixed in 7.2.0-1)
bullseye: resolved (fixed in 7.2.0-1)
forky: resolved (fixed in 7.2.0-1)
sid: resolved (fixed in 7.2.0-1)
trixie: resolved (fixed in 7.2.0-1)
debian
CVE-2020-10994P4LOWCVSS 5.5fixed in pillow 7.2.0-1 (bookworm)2020
CVE-2020-10994 [MEDIUM] CVE-2020-10994: pillow - In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-b...
In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.
Scope: local
bookworm: resolved (fixed in 7.2.0-1)
bullseye: resolved (fixed in 7.2.0-1)
forky: resolved (fixed in 7.2.0-1)
sid: resolved (fixed in 7.2.0-1)
trixie: resolved (fixed in 7.2.0-1)
debian
CVE-2021-28675P4MEDIUMCVSS 5.5fixed in pillow 8.1.2+dfsg-0.2 (bookworm)2021
CVE-2021-28675 [MEDIUM] CVE-2021-28675: pillow - An issue was discovered in Pillow before 8.2.0. PSDImagePlugin.PsdImageFile lack...
An issue was discovered in Pillow before 8.2.0. PSDImagePlugin.PsdImageFile lacked a sanity check on the number of input layers relative to the size of the data block. This could lead to a DoS on Image.open prior to Image.load.
Scope: local
bookworm: resolved (fixed in 8.1.2+dfsg-0.2)
bullseye: resolved (fixed in 8.1.2+dfsg-0.2)
forky: resolved (fixed in 8.1.2+dfsg
debian
CVE-2021-28678P4MEDIUMCVSS 5.5fixed in pillow 8.1.2+dfsg-0.2 (bookworm)2021
CVE-2021-28678 [MEDIUM] CVE-2021-28678: pillow - An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did...
An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.
Scope: local
bookworm: resolved (fixed in 8.1.2+dfsg-0.2)
bullseye: resolved (fixed in 8.1.2+dfsg-0.2)
forky: reso
debian
CVE-2014-1932P4LOWCVSS 4.4fixed in pillow 2.4.0-1 (bookworm)2014
CVE-2014-1932 [MEDIUM] CVE-2014-1932: pillow - The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in E...
The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 do not properly create temporary files, which allow local users to overwrite arbitrary files and obtain sensitive informati
debian
CVE-2014-1933P4LOWCVSS 2.1fixed in pillow 2.4.0-1 (bookworm)2014
CVE-2014-1933 [LOW] CVE-2014-1933: pillow - The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Lib...
The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.
Scope: local
bookworm: resolved (fixed in 2.4.0-1)
bullseye: resolved (fixed in 2.4.0-1)
fork
debian
← Previous3 / 3