Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-25291

Опубликовано: 28 фев. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.

A flaw was found in python-pillow. Invalid tile boundaries could lead to an OOB Read in TiffReadRGBATile in TiffDecode.c.

Отчет

This issue does not affect the versions of python-pillow as shipped with Red Hat Enterprise Linux 8 as it does not include the vulnerable code, which was introduced in a newer upstream version than what what shipped.

Меры по смягчению последствий

Disable the invoice generation feature to mitigate this vulnerability in Red Hat Quay.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7python-pillowOut of support scope
Red Hat Enterprise Linux 8python-pillowNot affected
Red Hat Enterprise Linux 9python-pillowAffected
Red Hat Quay 3quay/quay-rhel8FixedRHSA-2021:391719.10.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1934692python-pillow: out-of-bounds read in TiffReadRGBATile in TiffDecode.c

EPSS

Процентиль: 67%
0.00539
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.

CVSS3: 7.5
nvd
почти 5 лет назад

An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.

CVSS3: 7.5
debian
почти 5 лет назад

An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there ...

CVSS3: 7.5
github
почти 5 лет назад

Out of bounds read in Pillow

suse-cvrf
больше 4 лет назад

Security update for python-CairoSVG, python-Pillow

EPSS

Процентиль: 67%
0.00539
Низкий

7.5 High

CVSS3

Уязвимость CVE-2021-25291