QID 982879
QID 982879: Python (pip) Security Update for Pillow (GHSA-9hx2-hgq2-2g4f)
An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a crafted PDF file because of a catastrophic backtracking regex.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-9hx2-hgq2-2g4f for updates pertaining to this vulnerability.
Vendor References
- GHSA-9hx2-hgq2-2g4f -
github.com/advisories/GHSA-9hx2-hgq2-2g4f
CVEs related to QID 982879
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9hx2-hgq2-2g4f | Pillow |
|