CVE-2021-28678
02.06.2021, 16:15
An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.Enginsight
| Vendor | Product | Version |
|---|---|---|
| python | pillow | 𝑥 < 8.2.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| pillow |
| ||||||||||||||||||||||||
| pillow-python2 |
| ||||||||||||||||||||||||
| python-imaging |
|
Common Weakness Enumeration
References