Python Pillow 8.3.1

CPE Details

Python Pillow 8.3.1
8.3.1
2021-07-15
13h35 +00:00
2021-07-15
13h38 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:python:pillow:8.3.1:*:*:*:*:*:*:*

Informations

Vendor

python

Product

pillow

Version

8.3.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-50447 2024-01-18 23h00 +00:00 Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
8.1
High
CVE-2023-44271 2023-11-02 23h00 +00:00 An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
7.5
High
CVE-2022-45198 2022-11-13 23h00 +00:00 Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
7.5
High
CVE-2022-45199 2022-11-13 23h00 +00:00 Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
7.5
High
CVE-2022-24303 2022-03-27 22h00 +00:00 Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
9.1
Critical
CVE-2022-22815 2022-01-06 23h00 +00:00 path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.
6.5
Medium
CVE-2022-22816 2022-01-06 23h00 +00:00 path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.
6.5
Medium
CVE-2022-22817 2022-01-06 23h00 +00:00 PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.
9.8
Critical
CVE-2021-23437 2021-09-03 16h10 +00:00 The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
7.5
High