CVE-2021-27922
published 2021-03-03CVE-2021-27922: Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.85%
91.0th percentile
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pillow | < pillow 8.1.2-1 (bookworm) | pillow 8.1.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| paloalto | pan-os | — | — |
| python | pillow | < 8.1.1 | 8.1.1 |
| python | pillow | >= 0 < 8.1.2-1 | 8.1.2-1 |
| python | pillow | >= 0 < 8.1.2-1 | 8.1.2-1 |
| python | pillow | >= 0 < 8.1.2-1 | 8.1.2-1 |
| python | pillow | >= 0 < 8.1.2-1 | 8.1.2-1 |
| python | pillow | >= 0 < 8.1.2 | 8.1.2 |
| python | pillow | >= 0 < 8.1.1 | 8.1.1 |
| python | pillow | >= 0 < 3.1.2-0ubuntu1.6 | 3.1.2-0ubuntu1.6 |
| python | pillow | >= 0 < 5.1.0-1ubuntu0.5 | 5.1.0-1ubuntu0.5 |
| python | pillow | >= 0 < 7.0.0-4ubuntu0.3 | 7.0.0-4ubuntu0.3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2021-03-11·CVSS 9.8
CVE-2021-27922 [CRITICAL] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
It was discovered that Pillow incorrectly handled certain Tiff image files.
If a user or automated system were tricked into opening a specially-crafted
Tiff file, a remote attacker could cause Pillow to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2021-25289,
CVE-2021-25291)
It was discovered that Pillow incorrectly handled certain Tiff image files.
If a user or automated system were tricked into opening a specially-crafted
Tiff file, a remote attacker could cause Pillow to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2021-25290)
It was discovered that Pillow incorrectly
Red Hat
python-pillow: Excessive memory allocation in ICNS image reader
vendor_redhat·2021-03-03·CVSS 7.5
CVE-2021-27922 [HIGH] CWE-1284 python-pillow: Excessive memory allocation in ICNS image reader
python-pillow: Excessive memory allocation in ICNS image reader
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.
A flaw was found in python-pillow. Attackers can cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.
Statement: Disable the invoice generation feature to mitigate this vulnerability in Red Hat Quay.
Package: python-pillow (Red Hat Enterprise Linux 7) - Out of support scope
Package: python-pillow (Red Hat Enterprise Linux 9) - Affected
Debian
CVE-2021-27922: pillow - Pillow before 8.1.2 allows attackers to cause a denial of service (memory consum...
vendor_debian·2021·CVSS 7.5
CVE-2021-27922 [HIGH] CVE-2021-27922: pillow - Pillow before 8.1.2 allows attackers to cause a denial of service (memory consum...
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.
Scope: local
bookworm: resolved (fixed in 8.1.2-1)
bullseye: resolved (fixed in 8.1.2-1)
forky: resolved (fixed in 8.1.2-1)
sid: resolved (fixed in 8.1.2-1)
trixie: resolved (fixed in 8.1.2-1)
GHSA
Pillow Uncontrolled Resource Consumption
ghsa·2021-03-18
CVE-2021-27922 [HIGH] CWE-20 Pillow Uncontrolled Resource Consumption
Pillow Uncontrolled Resource Consumption
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.
OSV
Pillow Uncontrolled Resource Consumption
osv·2021-03-18
CVE-2021-27922 [HIGH] Pillow Uncontrolled Resource Consumption
Pillow Uncontrolled Resource Consumption
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.
OSV
pillow vulnerabilities
osv·2021-03-11·CVSS 9.8
CVE-2021-25289 [CRITICAL] pillow vulnerabilities
pillow vulnerabilities
It was discovered that Pillow incorrectly handled certain Tiff image files.
If a user or automated system were tricked into opening a specially-crafted
Tiff file, a remote attacker could cause Pillow to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2021-25289,
CVE-2021-25291)
It was discovered that Pillow incorrectly handled certain Tiff image files.
If a user or automated system were tricked into opening a specially-crafted
Tiff file, a remote attacker could cause Pillow to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2021-25290)
It was discovered that Pillow incorrectly handled certain PDF files. If a
user or automated system were
OSV
CVE-2021-27922: Pillow before 8
osv·2021-03-03·CVSS 7.5
CVE-2021-27922 [HIGH] CVE-2021-27922: Pillow before 8
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.
OSV
CVE-2021-27922: Pillow before 8
osv·2021-03-03
CVE-2021-27922 CVE-2021-27922: Pillow before 8
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/[email protected]/message/S7G44Z33J4BNI2DPDROHWGVG2U7ZH5JU/https://lists.fedoraproject.org/archives/list/[email protected]/message/TQQY6472RX4J2SUJENWDZAWKTJJGP2ML/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZTSY25UJU7NJUFHH3HWT575LT4TDFWBZ/https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.htmlhttps://security.gentoo.org/glsa/202107-33https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S7G44Z33J4BNI2DPDROHWGVG2U7ZH5JU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQQY6472RX4J2SUJENWDZAWKTJJGP2ML/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZTSY25UJU7NJUFHH3HWT575LT4TDFWBZ/https://pillow.readthedocs.io/en/stable/releasenotes/8.1.1.htmlhttps://security.gentoo.org/glsa/202107-33
2021-03-03
Published