Affected packages

Alpine:v3.12 / py3-pillow

Package

Name
py3-pillow
Purl
pkg:apk/alpine/py3-pillow?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.2.2-r0

Alpine:v3.13 / py3-pillow

Package

Name
py3-pillow
Purl
pkg:apk/alpine/py3-pillow?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.2.2-r0

Alpine:v3.14 / py3-pillow

Package

Name
py3-pillow
Purl
pkg:apk/alpine/py3-pillow?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.2.2-r0

Alpine:v3.15 / py3-pillow

Package

Name
py3-pillow
Purl
pkg:apk/alpine/py3-pillow?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.2.2-r0

Git / github.com/python-pillow/pillow

Affected ranges

Type
GIT
Repo
https://github.com/python-pillow/pillow
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.0
1.2
1.7.6
1.7.7
1.7.8

2.*

2.0.0
2.1.0
2.2.0
2.2.1
2.2.2
2.3.0
2.5.0
2.6.0
2.6.0-rc1
2.7.0
2.8.0
2.8.1
2.9.0
2.9.0.dev0
2.9.0.dev1
2.9.0.dev2

3.*

3.0.0
3.1.0
3.1.0-rc1
3.2.0
3.3.0
3.3.1
3.4.0

4.*

4.0.0
4.0.0a
4.1.0
4.2.0
4.3.0

5.*

5.0.0
5.1.0
5.2.0
5.3.0
5.4.0

6.*

6.0.0
6.1.0
6.2.0
6.2.1

Database specific

{
    "vanir_signatures": [
        {
            "id": "CVE-2020-5311-655a3b71",
            "signature_type": "Line",
            "digest": {
                "line_hashes": [
                    "74394628443402872264910573382191555015",
                    "331322978970584824777287696594234124122",
                    "23182711350509848214109658018129134498",
                    "21295675298201514072661238004526791439",
                    "147362313223325050429672845411114095032",
                    "11728680069999553532564805891395609734",
                    "146542584084456442475866787063765149690",
                    "111995761264553157563801106692361300122",
                    "336894040779789205909693731782617387270",
                    "282092743345704169374304954216301115022",
                    "169513242581767477544127227679857517673",
                    "64785095045983690514758407603369230022",
                    "147362313223325050429672845411114095032",
                    "11728680069999553532564805891395609734",
                    "146542584084456442475866787063765149690",
                    "125630191536919897373952870166590578771",
                    "58373006746695298486896448352276165673",
                    "335858634260284363779854828498007781985",
                    "109186713654740590875643673206751540586",
                    "252524666320560104270511936646063661420",
                    "228363093971994857844065892422863375425",
                    "220845418040944005946317753051840329161",
                    "24059358200304628671709782237977515221",
                    "175644003446321522865613307084547865669",
                    "186816661014658657970488018787100125892",
                    "84551653920536917952441927246021476869",
                    "246616666101419533298827601867129363327",
                    "284404479206762129323202108270234175513",
                    "116356111928500685543966321177907648373"
                ],
                "threshold": 0.9
            },
            "target": {
                "file": "src/libImaging/SgiRleDecode.c"
            },
            "deprecated": false,
            "signature_version": "v1",
            "source": "https://github.com/python-pillow/pillow/commit/a79b65c47c7dc6fe623aadf09aa6192fc54548f3"
        },
        {
            "id": "CVE-2020-5311-7b789c14",
            "signature_type": "Function",
            "digest": {
                "function_hash": "23537580919283434488848292199174173919",
                "length": 503.0
            },
            "target": {
                "file": "src/libImaging/SgiRleDecode.c",
                "function": "expandrow2"
            },
            "deprecated": false,
            "signature_version": "v1",
            "source": "https://github.com/python-pillow/pillow/commit/a79b65c47c7dc6fe623aadf09aa6192fc54548f3"
        },
        {
            "id": "CVE-2020-5311-df88ec3e",
            "signature_type": "Function",
            "digest": {
                "function_hash": "189928262583536917268053492207105390628",
                "length": 441.0
            },
            "target": {
                "file": "src/libImaging/SgiRleDecode.c",
                "function": "expandrow"
            },
            "deprecated": false,
            "signature_version": "v1",
            "source": "https://github.com/python-pillow/pillow/commit/a79b65c47c7dc6fe623aadf09aa6192fc54548f3"
        },
        {
            "id": "CVE-2020-5311-e7784fba",
            "signature_type": "Function",
            "digest": {
                "function_hash": "48429839654790430206881399079807026749",
                "length": 2942.0
            },
            "target": {
                "file": "src/libImaging/SgiRleDecode.c",
                "function": "ImagingSgiRleDecode"
            },
            "deprecated": false,
            "signature_version": "v1",
            "source": "https://github.com/python-pillow/pillow/commit/a79b65c47c7dc6fe623aadf09aa6192fc54548f3"
        }
    ]
}