The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-pillowUpgrade py-pillow | Aug 22, 2024 | Sep 3, 2021 |
| Amazon Linux Ami 2 | — | Upgrade python-pillow-saneUpgrade python-pillow-debuginfoUpgrade python-pillow-tkUpgrade python-pillow-develUpgrade python-pillowUpgrade python-pillow-doc | Jul 21, 2023 | Sep 3, 2021 |
| Debian | — | Upgrade pillow | Mar 25, 2024 | Sep 3, 2021 |
| Freebsd | — | Upgrade py38-pillow | Nov 4, 2022 | Sep 3, 2021 |
| Gentoo Linux | — | Upgrade dev-python/pillow. | Nov 23, 2022 | Sep 3, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade python-pillow | Feb 24, 2022 | Sep 3, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade python-pillow | Nov 12, 2021 | Sep 3, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade python3-pillowUpgrade python2-pillow | Nov 2, 2021 | Sep 3, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade python3-pillow-helpUpgrade python3-pillow | Nov 12, 2021 | Sep 3, 2021 |
| Oracle Solaris | — | Upgrade library/python/pillow to version 8.3.2-11.4.39.0.1.107.0 on Solaris 11.4Upgrade library/python/pillow-37 to version 8.3.2-11.4.39.0.1.107.0 on Solaris 11.4Upgrade library/python/pillow-39 to version 8.3.2-11.4.39.0.1.107.0 on Solaris 11.4 | Nov 17, 2021 | Sep 3, 2021 |
| Suse | — | Upgrade python3-pillow-tkUpgrade python3-pillow | Aug 9, 2024 | Sep 3, 2021 |
| Ubuntu | — | Upgrade python3-pilUpgrade python3-pil (Ubuntu Pro)Upgrade python-pil (Ubuntu Pro)Upgrade python-pil | Jan 14, 2022 | Sep 3, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub