The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://snyk.io/vuln/SNYK-PYTHON-PILLOW-1319443 | patch release notes exploit third party advisory |
https://pillow.readthedocs.io/en/stable/releasenotes/8.3.2.html | release notes vendor advisory |
https://github.com/python-pillow/Pillow/commit/9e08eb8f78fdfd2f476e1b20b7cf38683754866b | third party advisory patch |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VKRCL7KKAKOXCVD7M6WC5OKFGL4L3SJT/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RNSG6VFXTAROGF7ACYLMAZNQV4EJ6I2C/ | vendor advisory |
https://security.gentoo.org/glsa/202211-10 | third party advisory vendor advisory |
https://lists.debian.org/debian-lts-announce/2024/03/msg00021.html | mailing list |