CVE-2021-23437
The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
02 / AFFECTED SOFTWARE
Affected packages
14 explicit affected versions
23 explicit affected versions
82 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
The package pillow from 0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
05 / REFERENCES
Further evidence
- https://github.com/python-pillow/Pillow/commit/9e08eb8f78fdfd2f476e1b20b7cf38683754866b
- https://lists.debian.org/debian-lts-announce/2024/03/msg00021.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RNSG6VFXTAROGF7ACYLMAZNQV4EJ6I2C/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VKRCL7KKAKOXCVD7M6WC5OKFGL4L3SJT/
- https://nvd.nist.gov/vuln/detail/CVE-2021-23437
- https://pillow.readthedocs.io/en/stable/releasenotes/8.3.2.html
- https://security.gentoo.org/glsa/202211-10
- https://snyk.io/vuln/SNYK-PYTHON-PILLOW-1319443
- https://github.com/advisories/GHSA-98vv-pw6r-q6q4
- https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2021-317.yaml
- https://github.com/python-pillow/Pillow
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RNSG6VFXTAROGF7ACYLMAZNQV4EJ6I2C
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VKRCL7KKAKOXCVD7M6WC5OKFGL4L3SJT
- https://lists.fedoraproject.org/archives/list/[email protected]/message/RNSG6VFXTAROGF7ACYLMAZNQV4EJ6I2C
- https://lists.fedoraproject.org/archives/list/[email protected]/message/VKRCL7KKAKOXCVD7M6WC5OKFGL4L3SJT