CVE-2021-27923
published 2021-03-03CVE-2021-27923: Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked…
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.07%
86.2th percentile
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pillow | < pillow 8.1.2-1 (bookworm) | pillow 8.1.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| paloalto | pan-os | — | — |
| python | pillow | < 8.1.1 | 8.1.1 |
| python | pillow | >= 0 < 8.1.2-1 | 8.1.2-1 |
| python | pillow | >= 0 < 8.1.2-1 | 8.1.2-1 |
| python | pillow | >= 0 < 8.1.2-1 | 8.1.2-1 |
| python | pillow | >= 0 < 8.1.2-1 | 8.1.2-1 |
| python | pillow | >= 0 < 8.1.1 | 8.1.1 |
| python | pillow | >= 0 < 8.1.2 | 8.1.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2021-03-11·CVSS 9.8
CVE-2021-27922 [CRITICAL] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
It was discovered that Pillow incorrectly handled certain Tiff image files.
If a user or automated system were tricked into opening a specially-crafted
Tiff file, a remote attacker could cause Pillow to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2021-25289,
CVE-2021-25291)
It was discovered that Pillow incorrectly handled certain Tiff image files.
If a user or automated system were tricked into opening a specially-crafted
Tiff file, a remote attacker could cause Pillow to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2021-25290)
It was discovered that Pillow incorrectly
Red Hat
python-pillow: Excessive memory allocation in ICO image reader
vendor_redhat·2021-03-03·CVSS 7.5
CVE-2021-27923 [HIGH] CWE-1284 python-pillow: Excessive memory allocation in ICO image reader
python-pillow: Excessive memory allocation in ICO image reader
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
A flaw was found in python-pillow. Attackers can cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
Mitigation: Disable the invoice generation feature to mitigate this vulnerability in Red Hat Quay.
Package: python-pillow (Red Hat Enterprise Linux 7) - Out of support scope
Package: python-pillow (Red Hat Enterprise Linux 9) - Affected
Debian
CVE-2021-27923: pillow - Pillow before 8.1.2 allows attackers to cause a denial of service (memory consum...
vendor_debian·2021·CVSS 7.5
CVE-2021-27923 [HIGH] CVE-2021-27923: pillow - Pillow before 8.1.2 allows attackers to cause a denial of service (memory consum...
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
Scope: local
bookworm: resolved (fixed in 8.1.2-1)
bullseye: resolved (fixed in 8.1.2-1)
forky: resolved (fixed in 8.1.2-1)
sid: resolved (fixed in 8.1.2-1)
trixie: resolved (fixed in 8.1.2-1)
GHSA
Pillow Denial of Service by Uncontrolled Resource Consumption
ghsa·2021-03-18
CVE-2021-27923 [HIGH] CWE-20 Pillow Denial of Service by Uncontrolled Resource Consumption
Pillow Denial of Service by Uncontrolled Resource Consumption
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
OSV
Pillow Denial of Service by Uncontrolled Resource Consumption
osv·2021-03-18
CVE-2021-27923 [HIGH] Pillow Denial of Service by Uncontrolled Resource Consumption
Pillow Denial of Service by Uncontrolled Resource Consumption
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
OSV
CVE-2021-27923: Pillow before 8
osv·2021-03-03
CVE-2021-27923 CVE-2021-27923: Pillow before 8
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
OSV
CVE-2021-27923: Pillow before 8
osv·2021-03-03·CVSS 7.5
CVE-2021-27923 [HIGH] CVE-2021-27923: Pillow before 8
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/[email protected]/message/S7G44Z33J4BNI2DPDROHWGVG2U7ZH5JU/https://lists.fedoraproject.org/archives/list/[email protected]/message/TQQY6472RX4J2SUJENWDZAWKTJJGP2ML/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZTSY25UJU7NJUFHH3HWT575LT4TDFWBZ/https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.htmlhttps://security.gentoo.org/glsa/202107-33https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S7G44Z33J4BNI2DPDROHWGVG2U7ZH5JU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQQY6472RX4J2SUJENWDZAWKTJJGP2ML/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZTSY25UJU7NJUFHH3HWT575LT4TDFWBZ/https://pillow.readthedocs.io/en/stable/releasenotes/8.1.1.htmlhttps://security.gentoo.org/glsa/202107-33
2021-03-03
Published