CVE-2021-34552
13.07.2021, 17:15
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| python | pillow | 1.0 ≤ 𝑥 ≤ 1.1.7 |
| python | pillow | 1.2 ≤ 𝑥 ≤ 8.2.0 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| pillow |
| ||||||||||||||||||||||||
| pillow-python2 |
| ||||||||||||||||||||||||
| python-imaging |
|
openSUSE / SLES Releases
openSUSE Product | |||||||
|---|---|---|---|---|---|---|---|
| python311-Pillow |
| ||||||
| python311-Pillow-tk |
|
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| python-pillow |
| ||||
| python-pillow-debuginfo |
| ||||
| python-pillow-debugsource |
| ||||
| python-pillow-devel |
| ||||
| python-pillow-doc |
| ||||
| python-pillow-sane |
| ||||
| python-pillow-tk |
| ||||
| python3-pillow |
| ||||
| python3-pillow-debuginfo |
| ||||
| python3-pillow-devel |
| ||||
| python3-pillow-tk |
| ||||
| python3-pillow-tk-debuginfo |
|
References