vulnerability
FreeBSD: VID-f947aa26-b2f9-11eb-a5f7-a0f3c100ae18 (CVE-2021-28678): Pillow -- multiple vulnerabilities
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:M/Au:N/C:N/I:N/A:P) | May 12, 2021 | Nov 4, 2022 | Dec 10, 2025 |
Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
May 12, 2021
Added
Nov 4, 2022
Modified
Dec 10, 2025
Description
python-pillow reports: This release fixes several vulnerabilities found with `OSS-Fuzz`. `CVE-2021-25288`: Fix OOB read in Jpeg2KDecode. This dates to Pillow 2.4.0. `CVE-2021-28675`: Fix DOS in PsdImagePlugin. This dates to the PIL fork. `CVE-2021-28676`: Fix FLI DOS. This dates to the PIL fork. `CVE-2021-28677`: Fix EPS DOS on _open. This dates to the PIL fork. `CVE-2021-28678`: Fix BLP DOS. This dates to Pillow 5.1.0. Fix memory DOS in ImageFont. This dates to the PIL fork.
Solution
freebsd-upgrade-package-py38-pillow
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.