PT-2022-28191 · Pillow · Pillow

Published

2022-03-11

·

Updated

2022-03-11

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Pillow (affected versions not specified)
Description The issue concerns the JpegImagePlugin, which may append an EOF marker to the end of a truncated file. If this EOF marker is not properly detected, it could lead to an infinite loop where the plugin continuously attempts to process the file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-4FX9-VC88-Q2XC

Affected Products

Pillow