An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for CVE-2020-35654.
References
Link | Resource |
---|---|
https://pillow.readthedocs.io/en/stable/releasenotes/8.1.1.html | Release Notes Vendor Advisory |
https://security.gentoo.org/glsa/202107-33 | Third Party Advisory |
Configurations
Information
Published : 2021-03-18 21:15
Updated : 2021-12-01 09:03
NVD link : CVE-2021-25289
Mitre link : CVE-2021-25289
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
python
- pillow