FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Pillow -- Regular Expression Denial of Service (ReDoS)

Affected packages
5.2.0 <= py38-pillow < 8.3.2

Details

VuXML ID ed8a4215-675c-11ec-8dd4-a0f3c100ae18
Discovery 2021-09-02
Entry 2021-09-03

GitHub Advisory Database reports:

Uncontrolled Resource Consumption in pillow.

The package pillow from 0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.

References:

References

CVE Name CVE-2021-23437
URL https://nvd.nist.gov/vuln/detail/CVE-2021-23437