CVE-2021-27921
published 2021-03-03CVE-2021-27921: Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked…
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.17%
86.6th percentile
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pillow | < pillow 8.1.2-1 (bookworm) | pillow 8.1.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| paloalto | pan-os | — | — |
| python | pillow | < 8.1.1 | 8.1.1 |
| python | pillow | >= 0 < 8.1.2-1 | 8.1.2-1 |
| python | pillow | >= 0 < 8.1.2-1 | 8.1.2-1 |
| python | pillow | >= 0 < 8.1.2-1 | 8.1.2-1 |
| python | pillow | >= 0 < 8.1.2-1 | 8.1.2-1 |
| python | pillow | >= 0 < 8.1.2 | 8.1.2 |
| python | pillow | >= 0 < 8.1.1 | 8.1.1 |
| python | pillow | >= 0 < 3.1.2-0ubuntu1.6 | 3.1.2-0ubuntu1.6 |
| python | pillow | >= 0 < 5.1.0-1ubuntu0.5 | 5.1.0-1ubuntu0.5 |
| python | pillow | >= 0 < 7.0.0-4ubuntu0.3 | 7.0.0-4ubuntu0.3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa7.5HIGH
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2021-03-11·CVSS 9.8
CVE-2021-27922 [CRITICAL] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
It was discovered that Pillow incorrectly handled certain Tiff image files.
If a user or automated system were tricked into opening a specially-crafted
Tiff file, a remote attacker could cause Pillow to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2021-25289,
CVE-2021-25291)
It was discovered that Pillow incorrectly handled certain Tiff image files.
If a user or automated system were tricked into opening a specially-crafted
Tiff file, a remote attacker could cause Pillow to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2021-25290)
It was discovered that Pillow incorrectly
Red Hat
python-pillow: Excessive memory allocation in BLP image reader
vendor_redhat·2021-03-03·CVSS 7.5
CVE-2021-27921 [HIGH] CWE-1284 python-pillow: Excessive memory allocation in BLP image reader
python-pillow: Excessive memory allocation in BLP image reader
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
A flaw was found in python-pillow. Attackers can cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
Mitigation: Disable the invoice generation feature to mitigate this vulnerability in Red Hat Quay.
Package: python-pillow (Red Hat Enterprise Linux 7) - Out of support scope
Package: python-pillow (Red Hat Enterprise Linux 9) - Affected
Debian
CVE-2021-27921: pillow - Pillow before 8.1.2 allows attackers to cause a denial of service (memory consum...
vendor_debian·2021·CVSS 7.5
CVE-2021-27921 [HIGH] CVE-2021-27921: pillow - Pillow before 8.1.2 allows attackers to cause a denial of service (memory consum...
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
Scope: local
bookworm: resolved (fixed in 8.1.2-1)
bullseye: resolved (fixed in 8.1.2-1)
forky: resolved (fixed in 8.1.2-1)
sid: resolved (fixed in 8.1.2-1)
trixie: resolved (fixed in 8.1.2-1)
OSV
Uncontrolled Resource Consumption in pillow
osv·2021-04-23·CVSS 7.5
[HIGH] Uncontrolled Resource Consumption in pillow
Uncontrolled Resource Consumption in pillow
### Impact
_Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large._
### Patches
_An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image._
### Workarounds
_An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image._
### References
https:
GHSA
Uncontrolled Resource Consumption in pillow
ghsa·2021-04-23·CVSS 7.5
[HIGH] CWE-400 Uncontrolled Resource Consumption in pillow
Uncontrolled Resource Consumption in pillow
### Impact
_Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large._
### Patches
_An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image._
### Workarounds
_An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image._
### References
https:
GHSA
Pillow Denial of Service by Uncontrolled Resource Consumption
ghsa·2021-03-18
CVE-2021-27921 [HIGH] CWE-20 Pillow Denial of Service by Uncontrolled Resource Consumption
Pillow Denial of Service by Uncontrolled Resource Consumption
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
OSV
Pillow Denial of Service by Uncontrolled Resource Consumption
osv·2021-03-18
CVE-2021-27921 [HIGH] Pillow Denial of Service by Uncontrolled Resource Consumption
Pillow Denial of Service by Uncontrolled Resource Consumption
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
OSV
pillow vulnerabilities
osv·2021-03-11·CVSS 9.8
CVE-2021-25289 [CRITICAL] pillow vulnerabilities
pillow vulnerabilities
It was discovered that Pillow incorrectly handled certain Tiff image files.
If a user or automated system were tricked into opening a specially-crafted
Tiff file, a remote attacker could cause Pillow to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2021-25289,
CVE-2021-25291)
It was discovered that Pillow incorrectly handled certain Tiff image files.
If a user or automated system were tricked into opening a specially-crafted
Tiff file, a remote attacker could cause Pillow to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2021-25290)
It was discovered that Pillow incorrectly handled certain PDF files. If a
user or automated system were
OSV
CVE-2021-27921: Pillow before 8
osv·2021-03-03·CVSS 7.5
CVE-2021-27921 [HIGH] CVE-2021-27921: Pillow before 8
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
OSV
CVE-2021-27921: Pillow before 8
osv·2021-03-03
CVE-2021-27921 CVE-2021-27921: Pillow before 8
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
No detection rules found.
No public exploits indexed.
https://lists.fedoraproject.org/archives/list/[email protected]/message/S7G44Z33J4BNI2DPDROHWGVG2U7ZH5JU/https://lists.fedoraproject.org/archives/list/[email protected]/message/TQQY6472RX4J2SUJENWDZAWKTJJGP2ML/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZTSY25UJU7NJUFHH3HWT575LT4TDFWBZ/https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.htmlhttps://security.gentoo.org/glsa/202107-33https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S7G44Z33J4BNI2DPDROHWGVG2U7ZH5JU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQQY6472RX4J2SUJENWDZAWKTJJGP2ML/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZTSY25UJU7NJUFHH3HWT575LT4TDFWBZ/https://pillow.readthedocs.io/en/stable/releasenotes/8.1.1.htmlhttps://security.gentoo.org/glsa/202107-33
2021-03-03
Published