Severity
9.8CRITICALNVD
OSV7.5
EPSS
0.3%
top 43.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 13
Latest updateApr 10

Description

Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

PyPIpython/pillow< 8.3.0
Debianpython/pillow< 8.1.2+dfsg-0.3+3
Ubuntupython/pillow< 5.1.0-1ubuntu0.8+5
NVDpython/pillow1.01.1.7+1
Palo Altopaloalto/pan-os

Also affects: Debian Linux 9.0, Fedora 33, 34

🔴Vulnerability Details

7
OSV
pillow vulnerability2022-10-24
OSV
pillow vulnerabilities2022-01-17
OSV
pillow vulnerabilities2022-01-13
GHSA
Buffer Overflow in Pillow2021-10-05
OSV
Buffer Overflow in Pillow2021-10-05

📋Vendor Advisories

6
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS2024-04-10
Ubuntu
Pillow vulnerability2022-10-24
Ubuntu
Pillow vulnerabilities2022-01-17
Ubuntu
Pillow vulnerabilities2022-01-13
Red Hat
python-pillow: Buffer overflow in image convert function2021-07-13
CVE-2021-34552 — Classic Buffer Overflow in Python | cvebase