CVE-2021-23437
Summary
| CVE | CVE-2021-23437 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-03 16:15:00 UTC |
| Updated | 2023-11-07 03:30:00 UTC |
| Description | The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Regular Expression Denial of Service (ReDoS) in pillow | Snyk |
CONFIRM |
snyk.io |
|
| [SECURITY] Fedora 34 Update: mingw-python-pillow-8.1.2-4.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: mingw-python-pillow-8.1.2-4.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Pillow: Multiple Vulnerabilities (GLSA 202211-10) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Raise ValueError if color specifier is too long · python-pillow/Pillow@9e08eb8 · GitHub |
CONFIRM |
github.com |
|
| [SECURITY] Fedora 33 Update: python2-pillow-6.2.2-7.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| 8.3.2 — Pillow (PIL Fork) 8.3.2 documentation |
CONFIRM |
pillow.readthedocs.io |
|
| [SECURITY] Fedora 33 Update: python2-pillow-6.2.2-7.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Liyuan Chen
Legacy QID Mappings
- 182687 Debian Security Update for pillow (CVE-2021-23437)
- 198632 Ubuntu Security Notification for Pillow Vulnerabilities (USN-5227-1)
- 281922 Fedora Security Update for mingw (FEDORA-2021-9f020cf155)
- 281923 Fedora Security Update for mingw (FEDORA-2021-cbfaefb390)
- 296065 Oracle Solaris 11.4 Support Repository Update (SRU) 39.107.1 Missing (CPUOCT2021)
- 355610 Amazon Linux Security Advisory for python-pillow : ALAS2-2023-2118
- 375872 Python Pillow Library Denial of Service (DoS) Vulnerability
- 500782 Alpine Linux Security Update for py3-pillow
- 501477 Alpine Linux Security Update for py3-pillow
- 501769 Alpine Linux Security Update for py3-pillow
- 502017 Alpine Linux Security Update for py3-pillow
- 6000536 Debian Security Update for pillow (DLA 3768-1)
- 670840 EulerOS Security Update for python-pillow (EulerOS-SA-2021-2719)
- 670980 EulerOS Security Update for python-pillow (EulerOS-SA-2021-2641)
- 670999 EulerOS Security Update for python-pillow (EulerOS-SA-2021-2670)
- 671003 EulerOS Security Update for python-pillow (EulerOS-SA-2021-2694)
- 671249 EulerOS Security Update for python-pillow (EulerOS-SA-2022-1184)
- 690755 Free Berkeley Software Distribution (FreeBSD) Security Update for pillow (ed8a4215-675c-11ec-8dd4-a0f3c100ae18)
- 710682 Gentoo Linux Pillow Multiple Vulnerabilities (GLSA 202211-10)
- 980786 Python (pip) Security Update for pillow (GHSA-98vv-pw6r-q6q4)