CVE-2021-27921
HIGHPillow < 8.1.2 - Denial of Service via BLP Image Size Mismatch
Title source: llmDescription
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
References (9)
Core 9
Core References
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/ZTSY25UJU7NJUFHH3HWT575LT4TDFWBZ/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/TQQY6472RX4J2SUJENWDZAWKTJJGP2ML/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/S7G44Z33J4BNI2DPDROHWGVG2U7ZH5JU/
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202107-33
Various Sources
https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html
Release Notes, Vendor Advisory
https://pillow.readthedocs.io/en/stable/releasenotes/8.1.1.html
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S7G44Z33J4BNI2DPDROHWGVG2U7ZH5JU/
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQQY6472RX4J2SUJENWDZAWKTJJGP2ML/
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZTSY25UJU7NJUFHH3HWT575LT4TDFWBZ/
Scores
CVSS v3
7.5
EPSS
0.0043
EPSS Percentile
62.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-20
Status
published
Products (5)
fedoraproject/fedora
32
fedoraproject/fedora
33
fedoraproject/fedora
34
pypi/Pillow
0 - 8.1.2PyPI
python/pillow
< 8.1.1
Published
Mar 03, 2021
Tracked Since
Feb 18, 2026