Description
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2716-1 | pillow security update |
EUVD |
EUVD-2021-0173 | An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size. |
Github GHSA |
GHSA-8xjq-8fcg-g5hw | Out-of-bounds Write in Pillow |
Ubuntu USN |
USN-4763-1 | Pillow vulnerabilities |
Ubuntu USN |
USN-8135-1 | Pillow vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T19:56:11.089Z
Reserved: 2021-01-17T00:00:00.000Z
Link: CVE-2021-25290
No data.
Status : Modified
Published: 2021-03-19T04:15:13.357
Modified: 2024-11-21T05:54:41.427
Link: CVE-2021-25290
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN