Lucene search

K
freebsdFreeBSDF947AA26-B2F9-11EB-A5F7-A0F3C100AE18
HistoryApr 01, 2021 - 12:00 a.m.

Pillow -- multiple vulnerabilities

2021-04-0100:00:00
vuxml.freebsd.org
29
pillow
vulnerabilities
oob read
dos
memory
fix
jpeg2kdecode
psdimageplugin
fli
eps
blp dos
pil fork
unix

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

EPSS

0.004

Percentile

72.0%

python-pillow reports:

This release fixes several vulnerabilities found with OSS-Fuzz.

CVE-2021-25288: Fix OOB read in Jpeg2KDecode.
This dates to Pillow 2.4.0.
CVE-2021-28675: Fix DOS in PsdImagePlugin.
This dates to the PIL fork.
CVE-2021-28676: Fix FLI DOS.
This dates to the PIL fork.
CVE-2021-28677: Fix EPS DOS on _open.
This dates to the PIL fork.
CVE-2021-28678: Fix BLP DOS.
This dates to Pillow 5.1.0.
Fix memory DOS in ImageFont.
This dates to the PIL fork.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchpy38-pillow< 8.2.0UNKNOWN

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

EPSS

0.004

Percentile

72.0%