VYPR

rpm package

almalinux/python3-pillow

pkg:rpm/almalinux/python3-pillow

Vulnerabilities (26)

  • CVE-2021-25290HigMar 19, 2021
    affected < 5.1.1-16.el8fixed 5.1.1-16.el8

    An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.

  • CVE-2021-27923HigMar 3, 2021
    affected < 5.1.1-16.el8fixed 5.1.1-16.el8

    Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.

  • CVE-2021-27922HigMar 3, 2021
    affected < 5.1.1-16.el8fixed 5.1.1-16.el8

    Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.

  • CVE-2021-27921HigMar 3, 2021
    affected < 5.1.1-16.el8fixed 5.1.1-16.el8

    Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.

  • CVE-2020-35655MedJan 12, 2021
    affected < 5.1.1-16.el8fixed 5.1.1-16.el8

    In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.

  • CVE-2020-35653HigJan 12, 2021
    affected < 5.1.1-16.el8fixed 5.1.1-16.el8

    In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations.

Page 2 of 2