CVE-2021-34552
13.07.2021, 17:15
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
| Vendor | Product | Version |
|---|---|---|
| python | pillow | 1.0 ≤ 𝑥 ≤ 1.1.7 |
| python | pillow | 1.2 ≤ 𝑥 ≤ 8.2.0 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| pillow |
| ||||||||||||||||||||||||
| pillow-python2 |
| ||||||||||||||||||||||||
| python-imaging |
|
References