CVE-2021-34552
published 2021-07-13CVE-2021-34552: Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.16%
86.5th percentile
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | pillow | < pillow 8.1.2+dfsg-0.3 (bookworm) | pillow 8.1.2+dfsg-0.3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| paloalto | pan-os | — | — |
| python | pillow | >= 0 < 8.1.2+dfsg-0.3 | 8.1.2+dfsg-0.3 |
| python | pillow | >= 0 < 8.1.2+dfsg-0.3 | 8.1.2+dfsg-0.3 |
| python | pillow | >= 0 < 8.1.2+dfsg-0.3 | 8.1.2+dfsg-0.3 |
| python | pillow | >= 0 < 8.1.2+dfsg-0.3 | 8.1.2+dfsg-0.3 |
| python | pillow | >= 0 < 8.3.0 | 8.3.0 |
| python | pillow | >= 0 < 5.1.0-1ubuntu0.8 | 5.1.0-1ubuntu0.8 |
| python | pillow | >= 0 < 5.1.0-1ubuntu0.7 | 5.1.0-1ubuntu0.7 |
| python | pillow | >= 0 < 7.0.0-4ubuntu0.6 | 7.0.0-4ubuntu0.6 |
| python | pillow | >= 0 < 7.0.0-4ubuntu0.5 | 7.0.0-4ubuntu0.5 |
| python | pillow | >= 0 < 2.3.0-1ubuntu3.4+esm3 | 2.3.0-1ubuntu3.4+esm3 |
| python | pillow | >= 0 < 3.1.2-0ubuntu1.6+esm1 | 3.1.2-0ubuntu1.6+esm1 |
| python | pillow | 1.0 – 1.1.7 | — |
| python | pillow | 1.2 – 8.2.0 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
pillow vulnerability
osv·2022-10-24·CVSS 7.5
CVE-2022-22817 [HIGH] pillow vulnerability
pillow vulnerability
USN-5227-1 fixed vulnerabilities in Pillow. It was discovered that the fix
for CVE-2022-22817 was incomplete. This update fixes the problem.
Original advisory details:
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to hang, resulting in a denial
of service. (CVE-2021-23437)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to crash, resulting in a denial
of service. This issue ony affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and
Ubuntu 21.04. (CVE-2021-34552)
It was discovered that Pill
OSV
pillow vulnerabilities
osv·2022-01-17·CVSS 7.5
CVE-2021-23437 [HIGH] pillow vulnerabilities
pillow vulnerabilities
USN-5227-1 fixed several vulnerabilities in Pillow. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to hang, resulting in a denial
of service. (CVE-2021-23437)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to crash, resulting in a denial
of service. This issue ony affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and
Ubuntu 21.04. (CVE-2021-34552)
It was discovered that Pi
OSV
pillow vulnerabilities
osv·2022-01-13·CVSS 7.5
CVE-2021-23437 [HIGH] pillow vulnerabilities
pillow vulnerabilities
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to hang, resulting in a denial
of service. (CVE-2021-23437)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to crash, resulting in a denial
of service. This issue ony affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and
Ubuntu 21.04. (CVE-2021-34552)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to cr
GHSA
Buffer Overflow in Pillow
ghsa·2021-10-05
CVE-2021-34552 [CRITICAL] CWE-120 Buffer Overflow in Pillow
Buffer Overflow in Pillow
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
OSV
Buffer Overflow in Pillow
osv·2021-10-05
CVE-2021-34552 [CRITICAL] Buffer Overflow in Pillow
Buffer Overflow in Pillow
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
OSV
CVE-2021-34552: Pillow through 8
osv·2021-07-13·CVSS 9.8
CVE-2021-34552 [CRITICAL] CVE-2021-34552: Pillow through 8
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-04-10·CVSS 9.8
CVE-2015-5739 [CRITICAL] PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2015-5739 This CVE is fixed in PAN-OS 11.0.4, and all later PAN-OS versions. CVE-2016-10228 This CVE is fixed in PAN-OS 11.1.3, and all later PAN-OS versions. CVE-2017-8923 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2017-9120 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2018-25009 This CVE is fixed in PAN-OS 10.2.8, 11.0.4, 11.1.3, and all later PAN-OS versions. CVE-2
Ubuntu
Pillow vulnerability
vendor_ubuntu·2022-10-24·CVSS 7.5
CVE-2022-22817 [HIGH] Pillow vulnerability
Title: Pillow vulnerability
Summary: An incomplete fix was discovered in Pillow.
USN-5227-1 fixed vulnerabilities in Pillow. It was discovered that the fix
for CVE-2022-22817 was incomplete. This update fixes the problem.
Original advisory details:
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to hang, resulting in a denial
of service. (CVE-2021-23437)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to crash, resulting in a denial
of service. This issue ony affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, an
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2022-01-17·CVSS 7.5
CVE-2021-23437 [HIGH] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
USN-5227-1 fixed several vulnerabilities in Pillow. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to hang, resulting in a denial
of service. (CVE-2021-23437)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to crash, resulting in a denial
of service. This issue ony affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2022-01-13·CVSS 7.5
CVE-2022-22817 [HIGH] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to hang, resulting in a denial
of service. (CVE-2021-23437)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to crash, resulting in a denial
of service. This issue ony affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and
Ubuntu 21.04. (CVE-2021-34552)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a spe
Red Hat
python-pillow: Buffer overflow in image convert function
vendor_redhat·2021-07-13·CVSS 9.8
CVE-2021-34552 [CRITICAL] CWE-119 python-pillow: Buffer overflow in image convert function
python-pillow: Buffer overflow in image convert function
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
A flaw was found in python-pillow. This flaw allows an attacker to pass controlled parameters directly into a convert function, triggering a buffer overflow in the "convert()" or "ImagingConvertTransparent()" functions in Convert.c. The highest threat to this vulnerability is to system availability.
In Red Hat Quay, a vulnerable version of python-pillow is shipped with quay-registry-container, however the invoice generation feature which uses python-pillow is disabled by default. Therefore impact has been rated Moderate.
Statement: Due to
Debian
CVE-2021-34552: pillow - Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an...
vendor_debian·2021·CVSS 9.8
CVE-2021-34552 [CRITICAL] CVE-2021-34552: pillow - Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an...
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
Scope: local
bookworm: resolved (fixed in 8.1.2+dfsg-0.3)
bullseye: resolved (fixed in 8.1.2+dfsg-0.3)
forky: resolved (fixed in 8.1.2+dfsg-0.3)
sid: resolved (fixed in 8.1.2+dfsg-0.3)
trixie: resolved (fixed in 8.1.2+dfsg-0.3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2021/07/msg00018.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7V6LCG525ARIX6LX5QRYNAWVDD2MD2SV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VUGBBT63VL7G4JNOEIPDJIOC34ZFBKNJ/https://pillow.readthedocs.io/en/stable/releasenotes/8.3.0.html#buffer-overflowhttps://pillow.readthedocs.io/en/stable/releasenotes/index.htmlhttps://security.gentoo.org/glsa/202211-10https://lists.debian.org/debian-lts-announce/2021/07/msg00018.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7V6LCG525ARIX6LX5QRYNAWVDD2MD2SV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VUGBBT63VL7G4JNOEIPDJIOC34ZFBKNJ/https://pillow.readthedocs.io/en/stable/releasenotes/8.3.0.html#buffer-overflowhttps://pillow.readthedocs.io/en/stable/releasenotes/index.htmlhttps://security.gentoo.org/glsa/202211-10
2021-07-13
Published