<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:15:04 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:4149 — Moderate: python-pillow security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:4149</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python3-pillow&lt;/p&gt;
&lt;p&gt;The python-pillow packages contain a Python image processing library that provides extensive file format support, an efficient internal representation, and powerful image-processing capabilities.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-pillow: Out-of-bounds read in J2K image reader (CVE-2021-25287)&lt;/p&gt;
&lt;p&gt;* python-pillow: Out-of-bounds read in J2K image reader (CVE-2021-25288)&lt;/p&gt;
&lt;p&gt;* python-pillow: Negative-offset memcpy in TIFF image reader (CVE-2021-25290)&lt;/p&gt;
&lt;p&gt;* python-pillow: Regular expression DoS in PDF format parser (CVE-2021-25292)&lt;/p&gt;
&lt;p&gt;* python-pillow: Out-of-bounds read in SGI RLE image reader (CVE-2021-25293)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive memory allocation in BLP image reader (CVE-2021-27921)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive memory allocation in ICNS image reader (CVE-2021-27922)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive memory allocation in ICO image reader (CVE-2021-27923)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive memory allocation in PSD image reader (CVE-2021-28675)&lt;/p&gt;
&lt;p&gt;* python-pillow: Infinite loop in FLI image reader (CVE-2021-28676)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive CPU use in EPS image reader (CVE-2021-28677)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive looping in BLP image reader (CVE-2021-28678)&lt;/p&gt;
&lt;p&gt;* python-pillow: Buffer overflow in image convert function (CVE-2021-34552)&lt;/p&gt;
&lt;p&gt;* python-pillow: Buffer over-read in PCX image reader (CVE-2020-35653)&lt;/p&gt;
&lt;p&gt;* python-pillow: Buffer over-read in SGI RLE image reader (CVE-2020-35655)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related informati…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python3-pillow&lt;/p&gt;
&lt;p&gt;The python-pillow packages contain a Python image processing library that provides extensive file format support, an efficient internal representation, and powerful image-processing capabilities.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-pillow: Out-of-bounds read in J2K image reader (CVE-2021-25287)&lt;/p&gt;
&lt;p&gt;* python-pillow: Out-of-bounds read in J2K image reader (CVE-2021-25288)&lt;/p&gt;
&lt;p&gt;* python-pillow: Negative-offset memcpy in TIFF image reader (CVE-2021-25290)&lt;/p&gt;
&lt;p&gt;* python-pillow: Regular expression DoS in PDF format parser (CVE-2021-25292)&lt;/p&gt;
&lt;p&gt;* python-pillow: Out-of-bounds read in SGI RLE image reader (CVE-2021-25293)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive memory allocation in BLP image reader (CVE-2021-27921)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive memory allocation in ICNS image reader (CVE-2021-27922)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive memory allocation in ICO image reader (CVE-2021-27923)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive memory allocation in PSD image reader (CVE-2021-28675)&lt;/p&gt;
&lt;p&gt;* python-pillow: Infinite loop in FLI image reader (CVE-2021-28676)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive CPU use in EPS image reader (CVE-2021-28677)&lt;/p&gt;
&lt;p&gt;* python-pillow: Excessive looping in BLP image reader (CVE-2021-28678)&lt;/p&gt;
&lt;p&gt;* python-pillow: Buffer overflow in image convert function (CVE-2021-34552)&lt;/p&gt;
&lt;p&gt;* python-pillow: Buffer over-read in PCX image reader (CVE-2020-35653)&lt;/p&gt;
&lt;p&gt;* python-pillow: Buffer over-read in SGI RLE image reader (CVE-2020-35655)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related informati…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:4149</guid>
    </item>
    <item>
      <title>bdu:2021-05313</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-05313</link>
      <description>bdu:2021-05313</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-05313</guid>
    </item>
    <item>
      <title>BIT-pillow-2021-28677</title>
      <link>https://cve.radiocsirt.org/vuln/bit-pillow-2021-28677</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: pillow&lt;/p&gt;
&lt;p&gt;An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: pillow&lt;/p&gt;
&lt;p&gt;An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-pillow-2021-28677</guid>
    </item>
    <item>
      <title>BREW-pillow-CVE-2021-28677</title>
      <link>https://cve.radiocsirt.org/vuln/brew-pillow-cve-2021-28677</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: pillow&lt;/p&gt;
&lt;p&gt;An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: pillow&lt;/p&gt;
&lt;p&gt;An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-pillow-cve-2021-28677</guid>
    </item>
    <item>
      <title>cnvd-2021-54031</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-54031</link>
      <description>cnvd-2021-54031</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-54031</guid>
    </item>
    <item>
      <title>EUVD-2026-26058</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-26058</link>
      <description>EUVD-2026-26058</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-26058</guid>
    </item>
    <item>
      <title>fkie_cve-2021-28677</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-28677</link>
      <description>&lt;p&gt;An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-28677</guid>
    </item>
    <item>
      <title>GHSA-q5hq-fp76-qmrc — Uncontrolled Resource Consumption in Pillow</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q5hq-fp76-qmrc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q5hq-fp76-qmrc</guid>
    </item>
    <item>
      <title>gsd-2021-28677</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-28677</link>
      <description>gsd-2021-28677</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-28677</guid>
    </item>
    <item>
      <title>PYSEC-2021-93</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2021-93</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2021-93</guid>
    </item>
    <item>
      <title>RHSA-2021:4149 — Red Hat Security Advisory: python-pillow security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:4149</link>
      <description>&lt;p&gt;python-pillow: Buffer over-read in PCX image reader python-pillow: Buffer over-read in SGI RLE image reader python-pillow: Out-of-bounds read in J2K image reader python-pillow: Out-of-bounds read in J2K image reader python-pillow: Negative-offset memcpy in TIFF image reader python-pillow: Regular expression DoS in PDF format parser python-pillow: Out-of-bounds read in SGI RLE image reader python-pillow: Excessive memory allocation in BLP image reader python-pillow: Excessive memory allocation in ICNS image reader python-pillow: Excessive memory allocation in ICO image reader python-pillow: Excessive memory allocation in PSD image reader python-pillow: Infinite loop in FLI image reader python-pillow: Excessive CPU use in EPS image reader python-pillow: Excessive looping in BLP image reader python-pillow: Buffer overflow in image convert function&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python-pillow: Buffer over-read in PCX image reader python-pillow: Buffer over-read in SGI RLE image reader python-pillow: Out-of-bounds read in J2K image reader python-pillow: Out-of-bounds read in J2K image reader python-pillow: Negative-offset memcpy in TIFF image reader python-pillow: Regular expression DoS in PDF format parser python-pillow: Out-of-bounds read in SGI RLE image reader python-pillow: Excessive memory allocation in BLP image reader python-pillow: Excessive memory allocation in ICNS image reader python-pillow: Excessive memory allocation in ICO image reader python-pillow: Excessive memory allocation in PSD image reader python-pillow: Infinite loop in FLI image reader python-pillow: Excessive CPU use in EPS image reader python-pillow: Excessive looping in BLP image reader python-pillow: Buffer overflow in image convert function&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:4149</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:1938-1 — Security update for python-Pillow</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:1938-1</link>
      <description>&lt;p&gt;Security update for python-Pillow&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Pillow&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:1938-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-28677</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-28677</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: pillow, Ubuntu:Pro:16.04:LTS: pillow, Ubuntu:18.04:LTS: pillow, Ubuntu:20.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow-python2&lt;/p&gt;
&lt;p&gt;An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: pillow, Ubuntu:Pro:16.04:LTS: pillow, Ubuntu:18.04:LTS: pillow, Ubuntu:20.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow-python2&lt;/p&gt;
&lt;p&gt;An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-28677</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1835 — Red Hat Enterprise Linux (python-pillow): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1835</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in python-pillow ausnutzen, um einen Denial of Service Angriff durchzuführen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in python-pillow ausnutzen, um einen Denial of Service Angriff durchzuführen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1835</guid>
    </item>
  </channel>
</rss>
