AVG-1439 log

Package python2-pillow
Status Unknown
Severity Medium
Type multiple issues
Affected 6.2.1-3
Fixed Unknown
Current Removed
Ticket None
Created Tue Jan 12 10:01:10 2021
Issue Severity Remote Type Description
CVE-2021-27923 Low No Denial of service
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly...
CVE-2021-27922 Low No Denial of service
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly...
CVE-2021-27921 Low No Denial of service
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly...
CVE-2021-25293 Medium No Information disclosure
A security issue was found in python-pillow before version 8.1.1. There is an out of bounds read in SGIRleDecode.c, since pillow 4.3.0.
CVE-2021-25292 Low No Denial of service
A security issue was found in python-pillow before version 8.1.1. The PDF parser has a catastrophic backtracking regex that could be used in a denial of...
CVE-2021-25291 Medium No Information disclosure
A security issue was found in python-pillow before version 8.1.1. In TiffDecode.c, invalid tile boundaries could lead to an out of bounds read in TiffReadRGBATile.
CVE-2021-25290 Medium No Information disclosure
A security issue was found in python-pillow before version 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.
CVE-2021-25289 Medium No Arbitrary code execution
A security issue was found in python-pillow before version 8.1.1. The previous fix for CVE-2020-35654 was insufficent due to incorrect error checking in...
CVE-2020-35655 Low No Denial of service
In python-pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over- read when decoding crafted SGI RLE image files because offsets and length tables are...
CVE-2020-35654 Medium No Arbitrary code execution
In python-pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts...
CVE-2020-35653 Medium No Information disclosure
In python-pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for...
References
https://pillow.readthedocs.io/en/stable/releasenotes/8.1.0.html#security
Notes
python-pillow 7.0.0 dropped support for the end of life Python 2.7, so these issues are unlikely to be fixed in this legacy version of python-pillow, which is retained only for compatibility reasons.