Debian Pillow vulnerabilities
55 known vulnerabilities affecting debian/pillow.
Total CVEs
55
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH20MEDIUM17LOW10
Vulnerabilities
Page 3 of 3
CVE-2019-19911HIGHCVSS 7.5fixed in pillow 7.0.0-1 (bookworm)2019
CVE-2019-19911 [HIGH] CVE-2019-19911: pillow - There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py ...
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the
debian
CVE-2019-16865LOWCVSS 7.5fixed in pillow 6.2.0-1 (bookworm)2019
CVE-2019-16865 [HIGH] CVE-2019-16865: pillow - An issue was discovered in Pillow before 6.2.0. When reading specially crafted i...
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
Scope: local
bookworm: resolved (fixed in 6.2.0-1)
bullseye: resolved (fixed in 6.2.0-1)
forky: resolved (fixed in 6.2.0-1)
sid: resolved (fixed
debian
CVE-2016-4009CRITICALCVSS 9.8fixed in pillow 3.1.1-1 (bookworm)2016
CVE-2016-4009 [CRITICAL] CVE-2016-4009: pillow - Integer overflow in the ImagingResampleHorizontal function in libImaging/Resampl...
Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 3.1.1-1)
bullseye: resolved (fixed in 3.1.1-1)
forky: resolved (fixed in 3.1.1-1)
sid
debian
CVE-2016-9190HIGHCVSS 7.8fixed in pillow 3.4.2-1 (bookworm)2016
CVE-2016-9190 [HIGH] CVE-2016-9190: pillow - Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code...
Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.
Scope: local
bookworm: resolved (fixed in 3.4.2-1)
bullseye: resolved (fixed in 3.4.2-1)
forky: resolved (fixed in 3.4.2-1)
sid: resolved (fixed in 3.4
debian
CVE-2016-2533MEDIUMCVSS 6.5fixed in pillow 3.1.1-1 (bookworm)2016
CVE-2016-2533 [MEDIUM] CVE-2016-2533: pillow - Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before...
Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.
Scope: local
bookworm: resolved (fixed in 3.1.1-1)
bullseye: resolved (fixed in 3.1.1-1)
forky: resolved (fixed in 3.1.1-1)
sid: resolved (fix
debian
CVE-2016-0775MEDIUMCVSS 6.5fixed in pillow 3.1.1-1 (bookworm)2016
CVE-2016-0775 [MEDIUM] CVE-2016-0775: pillow - Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pi...
Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.
Scope: local
bookworm: resolved (fixed in 3.1.1-1)
bullseye: resolved (fixed in 3.1.1-1)
forky: resolved (fixed in 3.1.1-1)
sid: resolved (fixed in 3.1.1-1)
trixie: resolved (fixed in 3.
debian
CVE-2016-0740MEDIUMCVSS 6.5fixed in pillow 3.1.1-1 (bookworm)2016
CVE-2016-0740 [MEDIUM] CVE-2016-0740: pillow - Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c ...
Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.
Scope: local
bookworm: resolved (fixed in 3.1.1-1)
bullseye: resolved (fixed in 3.1.1-1)
forky: resolved (fixed in 3.1.1-1)
sid: resolved (fixed in 3.1.1-1)
trixie: resolved (fixed in 3.1.1-1)
debian
CVE-2016-9189MEDIUMCVSS 5.5fixed in pillow 3.4.2-1 (bookworm)2016
CVE-2016-9189 [MEDIUM] CVE-2016-9189: pillow - Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive infor...
Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.
Scope: local
bookworm: resolved (fixed in 3.4.2-1)
bullseye: resolved (fixed in 3.4.2-1)
forky: resolved (fixed in 3.4.2-1)
sid: resolved (fixe
debian
CVE-2016-3076LOWCVSS 5.5fixed in pillow 3.2.0-1 (bookworm)2016
CVE-2016-3076 [MEDIUM] CVE-2016-3076: pillow - Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 thro...
Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.
Scope: local
bookworm: resolved (fixed in 3.2.0-1)
bullseye: resolved (fixed in 3.2.0-1)
forky: resolved (fixed in 3.2.0-1)
sid: resolved (fixed in 3.2.0-1)
trixie: resolved (fi
debian
CVE-2014-9601MEDIUMCVSS 5.0fixed in pillow 2.6.1-2 (bookworm)2014
CVE-2014-9601 [MEDIUM] CVE-2014-9601: pillow - Pillow before 2.7.0 allows remote attackers to cause a denial of service via a c...
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
Scope: local
bookworm: resolved (fixed in 2.6.1-2)
bullseye: resolved (fixed in 2.6.1-2)
forky: resolved (fixed in 2.6.1-2)
sid: resolved (fixed in 2.6.1-2)
trixie: resolved (fixed in 2.6.1-2)
debian
CVE-2014-3007MEDIUMCVSS 4.4fixed in pillow 2.4.0-1 (bookworm)2014
CVE-2014-3007 [MEDIUM] CVE-2014-3007: pillow - Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote a...
Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py.
Scope: local
bookworm: resolved (fixed in 2.4.0-1)
bullseye: resolved (fixed in 2.4.0-1)
forky: resolved (fixed in 2.4.0-1)
sid: resolved (fixed in
debian
CVE-2014-3598MEDIUMCVSS 5.0fixed in pillow 2.5.3-1 (bookworm)2014
CVE-2014-3598 [MEDIUM] CVE-2014-3598: pillow - The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to c...
The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image.
Scope: local
bookworm: resolved (fixed in 2.5.3-1)
bullseye: resolved (fixed in 2.5.3-1)
forky: resolved (fixed in 2.5.3-1)
sid: resolved (fixed in 2.5.3-1)
trixie: resolved (fixed in 2.5.3-1)
debian
CVE-2014-3589MEDIUMCVSS 5.0fixed in pillow 2.5.3-1 (bookworm)2014
CVE-2014-3589 [MEDIUM] CVE-2014-3589: pillow - PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 a...
PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.
Scope: local
bookworm: resolved (fixed in 2.5.3-1)
bullseye: resolved (fixed in 2.5.3-1)
forky: resolved (fixed in 2.5.3-1)
sid: resolved (fixed in 2.5.3-1)
trixie: resolved (fixed in 2.5.
debian
CVE-2014-1933LOWCVSS 2.1fixed in pillow 2.4.0-1 (bookworm)2014
CVE-2014-1933 [LOW] CVE-2014-1933: pillow - The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Lib...
The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.
Scope: local
bookworm: resolved (fixed in 2.4.0-1)
bullseye: resolved (fixed in 2.4.0-1)
fork
debian
CVE-2014-1932LOWCVSS 4.4fixed in pillow 2.4.0-1 (bookworm)2014
CVE-2014-1932 [MEDIUM] CVE-2014-1932: pillow - The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in E...
The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 do not properly create temporary files, which allow local users to overwrite arbitrary files and obtain sensitive informati
debian
← Previous3 / 3