PT-2021-16503 · Pillow+4 · Pillow+4
Published
2021-03-03
·
Updated
2024-06-15
·
CVE-2021-25291
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Pillow versions prior to 8.1.1
Description:
An issue was discovered in Pillow, where there is an out-of-bounds read in
TiffreadRGBATile via invalid tile boundaries in TiffDecode.c.Recommendations:
For Pillow versions prior to 8.1.1, update to version 8.1.1 or later to resolve the issue.
As a temporary workaround, consider restricting the use of
TiffreadRGBATile function in TiffDecode.c until a patch is available.Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Pillow
Suse
Ubuntu