Описание
An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a crafted PDF file because of a catastrophic backtracking regex.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 5.1.0-1ubuntu0.5 |
| devel | not-affected | 8.1.2-1 |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra/bionic | released | 5.1.0-1ubuntu0.5 |
| esm-infra/focal | released | 7.0.0-4ubuntu0.3 |
| esm-infra/xenial | not-affected | code not present |
| focal | released | 7.0.0-4ubuntu0.3 |
| groovy | released | 7.2.0-1ubuntu0.2 |
| hirsute | not-affected | 8.1.2-1 |
| impish | not-affected | 8.1.2-1 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| esm-apps/focal | needs-triage | |
| esm-infra-legacy/trusty | DNE | |
| focal | ignored | end of standard support, was needs-triage |
| groovy | ignored | end of life |
| hirsute | DNE | |
| impish | DNE | |
| jammy | DNE | |
| kinetic | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| hirsute | DNE | |
| impish | DNE | |
| jammy | DNE | |
| kinetic | DNE |
Показывать по
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3
Связанные уязвимости
An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a crafted PDF file because of a catastrophic backtracking regex.
An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a crafted PDF file because of a catastrophic backtracking regex.
An issue was discovered in Pillow before 8.1.1. The PDF parser allows ...
Regular Expression Denial of Service (ReDoS) in Pillow
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3