OESA-2021-1383

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2021-1383
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2021-1383.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2021-1383
Upstream
Published
2021-10-15T11:03:15Z
Modified
2025-08-12T05:07:34.906639Z
Summary
python-pillow security update
Details

Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift.

Security Fix(es):

The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.(CVE-2021-23437)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / python-pillow

Package

Name
python-pillow
Purl
pkg:rpm/openEuler/python-pillow&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.1.1-7.oe1

Ecosystem specific

{
    "aarch64": [
        "python3-pillow-devel-8.1.1-7.oe1.aarch64.rpm",
        "python-pillow-debuginfo-8.1.1-7.oe1.aarch64.rpm",
        "python-pillow-debugsource-8.1.1-7.oe1.aarch64.rpm",
        "python3-pillow-qt-8.1.1-7.oe1.aarch64.rpm",
        "python3-pillow-8.1.1-7.oe1.aarch64.rpm",
        "python3-pillow-tk-8.1.1-7.oe1.aarch64.rpm"
    ],
    "noarch": [
        "python3-pillow-help-8.1.1-7.oe1.noarch.rpm"
    ],
    "x86_64": [
        "python3-pillow-tk-8.1.1-7.oe1.x86_64.rpm",
        "python-pillow-debugsource-8.1.1-7.oe1.x86_64.rpm",
        "python3-pillow-qt-8.1.1-7.oe1.x86_64.rpm",
        "python3-pillow-8.1.1-7.oe1.x86_64.rpm",
        "python-pillow-debuginfo-8.1.1-7.oe1.x86_64.rpm",
        "python3-pillow-devel-8.1.1-7.oe1.x86_64.rpm"
    ],
    "src": [
        "python-pillow-8.1.1-7.oe1.src.rpm"
    ]
}

openEuler:20.03-LTS-SP2 / python-pillow

Package

Name
python-pillow
Purl
pkg:rpm/openEuler/python-pillow&distro=openEuler-20.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.1.1-7.oe1

Ecosystem specific

{
    "aarch64": [
        "python3-pillow-8.1.1-7.oe1.aarch64.rpm",
        "python-pillow-debuginfo-8.1.1-7.oe1.aarch64.rpm",
        "python-pillow-debugsource-8.1.1-7.oe1.aarch64.rpm",
        "python3-pillow-devel-8.1.1-7.oe1.aarch64.rpm",
        "python3-pillow-tk-8.1.1-7.oe1.aarch64.rpm",
        "python3-pillow-qt-8.1.1-7.oe1.aarch64.rpm"
    ],
    "noarch": [
        "python3-pillow-help-8.1.1-7.oe1.noarch.rpm"
    ],
    "x86_64": [
        "python-pillow-debuginfo-8.1.1-7.oe1.x86_64.rpm",
        "python3-pillow-devel-8.1.1-7.oe1.x86_64.rpm",
        "python3-pillow-qt-8.1.1-7.oe1.x86_64.rpm",
        "python3-pillow-tk-8.1.1-7.oe1.x86_64.rpm",
        "python-pillow-debugsource-8.1.1-7.oe1.x86_64.rpm",
        "python3-pillow-8.1.1-7.oe1.x86_64.rpm"
    ],
    "src": [
        "python-pillow-8.1.1-7.oe1.src.rpm"
    ]
}