vulnerability

FreeBSD: VID-f947aa26-b2f9-11eb-a5f7-a0f3c100ae18 (CVE-2021-28678): Pillow -- multiple vulnerabilities

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
May 12, 2021
Added
Nov 4, 2022
Modified
Dec 10, 2025

Description

python-pillow reports: This release fixes several vulnerabilities found with `OSS-Fuzz`. `CVE-2021-25288`: Fix OOB read in Jpeg2KDecode. This dates to Pillow 2.4.0. `CVE-2021-28675`: Fix DOS in PsdImagePlugin. This dates to the PIL fork. `CVE-2021-28676`: Fix FLI DOS. This dates to the PIL fork. `CVE-2021-28677`: Fix EPS DOS on _open. This dates to the PIL fork. `CVE-2021-28678`: Fix BLP DOS. This dates to Pillow 5.1.0. Fix memory DOS in ImageFont. This dates to the PIL fork.

Solution

freebsd-upgrade-package-py38-pillow
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.