{"affected":[{"ecosystem_specific":{"binaries":[{"python3-Pillow":"7.2.0-150300.3.12.1","python3-Pillow-tk":"7.2.0-150300.3.12.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.5","name":"python-Pillow","purl":"pkg:rpm/opensuse/python-Pillow&distro=openSUSE%20Leap%2015.5"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"7.2.0-150300.3.12.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for python-Pillow fixes the following issues:\n\n- CVE-2021-25287: out-of-bounds read in J2kDecode in j2ku_graya_la (bsc#1185805)\n- CVE-2021-25288: out-of-bounds read in J2kDecode in j2ku_gray_i (bsc#1185803)\n- CVE-2021-28675: DoS in PsdImagePlugin (bsc#1185804)\n- CVE-2021-28676: infinite loop in FliDecode.c can lead to DoS (bsc#1185786)\n- CVE-2021-28677: DoS in the open phase via a malicious EPS file (bsc#1185785)\n- CVE-2021-28678: improper check in BlpImagePlugin can lead to DoS (bsc#1185784)\n","id":"SUSE-SU-2024:1607-1","modified":"2024-05-10T16:35:22Z","published":"2024-05-10T16:35:22Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2024/suse-su-20241607-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185784"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185785"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185786"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185803"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185804"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185805"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-25287"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-25288"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-28675"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-28676"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-28677"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-28678"}],"related":["CVE-2021-25287","CVE-2021-25288","CVE-2021-28675","CVE-2021-28676","CVE-2021-28677","CVE-2021-28678"],"summary":"Security update for python-Pillow","upstream":["CVE-2021-25287","CVE-2021-25288","CVE-2021-28675","CVE-2021-28676","CVE-2021-28677","CVE-2021-28678"]}