<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:20:20 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:4149 — Moderate: python-pillow security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:4149</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python3-pillow&lt;/p&gt;
&lt;p&gt;The python-pillow packages contain a Python image processing library that provides extensive file format support, an efficient internal representation, and powerful image-processing capabilities.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-pillow: Out-of-bounds read in J2K image reader (CVE-2021-25287)&lt;/p&gt;
&lt;p&gt;* python-pillow: Out-of-bounds read in J2K image reader (CVE-2021-25288)&lt;/p&gt;
&lt;p&gt;* python-pillow: Negative-offset memcpy in TIFF image reader (CVE-2021-25290)&lt;/p&gt;
&lt;p&gt;* python-pillow: Regular expression DoS in PDF format parser (CVE-2021-25292)&lt;/p&gt;
&lt;p&gt;* python-pillow: Out-of-bounds read in SGI RLE image reader (CVE-2021-25293)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive memory allocation in BLP image reader (CVE-2021-27921)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive memory allocation in ICNS image reader (CVE-2021-27922)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive memory allocation in ICO image reader (CVE-2021-27923)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive memory allocation in PSD image reader (CVE-2021-28675)&lt;/p&gt;
&lt;p&gt;* python-pillow: Infinite loop in FLI image reader (CVE-2021-28676)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive CPU use in EPS image reader (CVE-2021-28677)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive looping in BLP image reader (CVE-2021-28678)&lt;/p&gt;
&lt;p&gt;* python-pillow: Buffer overflow in image convert function (CVE-2021-34552)&lt;/p&gt;
&lt;p&gt;* python-pillow: Buffer over-read in PCX image reader (CVE-2020-35653)&lt;/p&gt;
&lt;p&gt;* python-pillow: Buffer over-read in SGI RLE image reader (CVE-2020-35655)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related informati…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python3-pillow&lt;/p&gt;
&lt;p&gt;The python-pillow packages contain a Python image processing library that provides extensive file format support, an efficient internal representation, and powerful image-processing capabilities.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-pillow: Out-of-bounds read in J2K image reader (CVE-2021-25287)&lt;/p&gt;
&lt;p&gt;* python-pillow: Out-of-bounds read in J2K image reader (CVE-2021-25288)&lt;/p&gt;
&lt;p&gt;* python-pillow: Negative-offset memcpy in TIFF image reader (CVE-2021-25290)&lt;/p&gt;
&lt;p&gt;* python-pillow: Regular expression DoS in PDF format parser (CVE-2021-25292)&lt;/p&gt;
&lt;p&gt;* python-pillow: Out-of-bounds read in SGI RLE image reader (CVE-2021-25293)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive memory allocation in BLP image reader (CVE-2021-27921)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive memory allocation in ICNS image reader (CVE-2021-27922)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive memory allocation in ICO image reader (CVE-2021-27923)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive memory allocation in PSD image reader (CVE-2021-28675)&lt;/p&gt;
&lt;p&gt;* python-pillow: Infinite loop in FLI image reader (CVE-2021-28676)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive CPU use in EPS image reader (CVE-2021-28677)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive looping in BLP image reader (CVE-2021-28678)&lt;/p&gt;
&lt;p&gt;* python-pillow: Buffer overflow in image convert function (CVE-2021-34552)&lt;/p&gt;
&lt;p&gt;* python-pillow: Buffer over-read in PCX image reader (CVE-2020-35653)&lt;/p&gt;
&lt;p&gt;* python-pillow: Buffer over-read in SGI RLE image reader (CVE-2020-35655)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related informati…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:4149</guid>
    </item>
    <item>
      <title>BIT-pillow-2020-35655</title>
      <link>https://cve.radiocsirt.org/vuln/bit-pillow-2020-35655</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: pillow&lt;/p&gt;
&lt;p&gt;In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: pillow&lt;/p&gt;
&lt;p&gt;In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-pillow-2020-35655</guid>
    </item>
    <item>
      <title>BREW-pillow-CVE-2020-35655</title>
      <link>https://cve.radiocsirt.org/vuln/brew-pillow-cve-2020-35655</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: pillow&lt;/p&gt;
&lt;p&gt;In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: pillow&lt;/p&gt;
&lt;p&gt;In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-pillow-cve-2020-35655</guid>
    </item>
    <item>
      <title>cnvd-2021-07117</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-07117</link>
      <description>cnvd-2021-07117</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-07117</guid>
    </item>
    <item>
      <title>EUVD-2026-47704</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-47704</link>
      <description>EUVD-2026-47704</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-47704</guid>
    </item>
    <item>
      <title>fkie_cve-2020-35655</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-35655</link>
      <description>&lt;p&gt;In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-35655</guid>
    </item>
    <item>
      <title>GHSA-hf64-x4gq-p99h — Pillow Out-of-bounds Read</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hf64-x4gq-p99h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hf64-x4gq-p99h</guid>
    </item>
    <item>
      <title>gsd-2020-35655</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-35655</link>
      <description>gsd-2020-35655</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-35655</guid>
    </item>
    <item>
      <title>OESA-2021-1127 — python-pillow security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1127</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: python-pillow&lt;/p&gt;
&lt;p&gt;Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.(CVE-2020-35655)&#13;
&#13;
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.(CVE-2021-27921)&#13;
&#13;
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.(CVE-2021-27922)&#13;
&#13;
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.(CVE-2021-27923)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: python-pillow&lt;/p&gt;
&lt;p&gt;Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.(CVE-2020-35655)&#13;
&#13;
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.(CVE-2021-27921)&#13;
&#13;
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.(CVE-2021-27922)&#13;
&#13;
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.(CVE-2021-27923)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1127</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:1134-1 — Security update for python-CairoSVG, python-Pillow</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1134-1</link>
      <description>&lt;p&gt;Security update for python-CairoSVG, python-Pillow&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-CairoSVG, python-Pillow&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:1134-1</guid>
    </item>
    <item>
      <title>PYSEC-2021-71</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2021-71</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2021-71</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:1938-1 — Security update for python-Pillow</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:1938-1</link>
      <description>&lt;p&gt;Security update for python-Pillow&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Pillow&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:1938-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-35655</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-35655</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: pillow, Ubuntu:20.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow-python2&lt;/p&gt;
&lt;p&gt;In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: pillow, Ubuntu:20.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow-python2&lt;/p&gt;
&lt;p&gt;In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-35655</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1835 — Red Hat Enterprise Linux (python-pillow): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1835</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in python-pillow ausnutzen, um einen Denial of Service Angriff durchzuführen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in python-pillow ausnutzen, um einen Denial of Service Angriff durchzuführen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1835</guid>
    </item>
  </channel>
</rss>
