CVE-2021-23437

The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
Configurations

Configuration 1 (hide)

cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

History

22 Mar 2024, 11:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/03/msg00021.html -

22 Nov 2022, 06:15

Type Values Removed Values Added
References
  • (GENTOO) https://security.gentoo.org/glsa/202211-10 -

30 Nov 2021, 21:19

Type Values Removed Values Added
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VKRCL7KKAKOXCVD7M6WC5OKFGL4L3SJT/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VKRCL7KKAKOXCVD7M6WC5OKFGL4L3SJT/ - Mailing List, Third Party Advisory
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RNSG6VFXTAROGF7ACYLMAZNQV4EJ6I2C/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RNSG6VFXTAROGF7ACYLMAZNQV4EJ6I2C/ - Mailing List, Third Party Advisory
References (CONFIRM) https://snyk.io/vuln/SNYK-PYTHON-PILLOW-1319443 - Exploit, Third Party Advisory (CONFIRM) https://snyk.io/vuln/SNYK-PYTHON-PILLOW-1319443 - Exploit, Patch, Release Notes, Third Party Advisory
CPE cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

22 Sep 2021, 11:15

Type Values Removed Values Added
Summary The package pillow from 0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function. The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.

21 Sep 2021, 17:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RNSG6VFXTAROGF7ACYLMAZNQV4EJ6I2C/ -
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VKRCL7KKAKOXCVD7M6WC5OKFGL4L3SJT/ -

10 Sep 2021, 19:09

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
CWE CWE-125
CPE cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*
References (CONFIRM) https://snyk.io/vuln/SNYK-PYTHON-PILLOW-1319443 - (CONFIRM) https://snyk.io/vuln/SNYK-PYTHON-PILLOW-1319443 - Exploit, Third Party Advisory
References (CONFIRM) https://github.com/python-pillow/Pillow/commit/9e08eb8f78fdfd2f476e1b20b7cf38683754866b - (CONFIRM) https://github.com/python-pillow/Pillow/commit/9e08eb8f78fdfd2f476e1b20b7cf38683754866b - Patch, Third Party Advisory
References (CONFIRM) https://pillow.readthedocs.io/en/stable/releasenotes/8.3.2.html - (CONFIRM) https://pillow.readthedocs.io/en/stable/releasenotes/8.3.2.html - Release Notes, Vendor Advisory

03 Sep 2021, 17:40

Type Values Removed Values Added
New CVE

Information

Published : 2021-09-03 16:15

Updated : 2024-03-22 11:15


NVD link : CVE-2021-23437

Mitre link : CVE-2021-23437

CVE.ORG link : CVE-2021-23437


JSON object : View

Products Affected

python

  • pillow

fedoraproject

  • fedora
CWE
CWE-125

Out-of-bounds Read