CVE-2021-28677
HIGHPython Pillow < 8.2.0 - Denial of Service
Title source: ruleDescription
An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.
References (5)
Scores
CVSS v3
7.5
EPSS
0.0026
EPSS Percentile
49.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
Status
published
Affected Products (3)
python/pillow
< 8.2.0
fedoraproject/fedora
pypi/pillow
< 8.2.0PyPI
Timeline
Published
Jun 02, 2021
Tracked Since
Feb 18, 2026