PT-2021-16503 · Pillow+4 · Pillow+4

Published

2021-03-03

·

Updated

2024-06-15

·

CVE-2021-25291

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Pillow versions prior to 8.1.1
Description: An issue was discovered in Pillow, where there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries in TiffDecode.c.
Recommendations: For Pillow versions prior to 8.1.1, update to version 8.1.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of TiffreadRGBATile function in TiffDecode.c until a patch is available.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1491
BIT-PILLOW-2021-25291
CVE-2021-25291
GHSA-MVG9-XFFR-P774
OPENSUSE-SU-2021:1134-1
OPENSUSE-SU-2021_1134-1
OPENSUSE-SU-2024:11209-1
OPENSUSE-SU-2024:13827-1
PYSEC-2021-37
USN-4763-1

Affected Products

Alt Linux
Linuxmint
Pillow
Suse
Ubuntu