CVE-2021-28678

MEDIUM

Pillow < 8.2.0 - Denial of Service via BLP Image Data Handling

Title source: llm
STIX 2.1

Description

An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.

References (4)

Core 4
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/python-pillow/Pillow/pull/5377
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202107-33

Scores

CVSS v3 5.5
EPSS 0.0011
EPSS Percentile 28.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-345
Status published
Products (3)
fedoraproject/fedora 33
pypi/Pillow 5.1.0 - 8.2.0PyPI
python/pillow < 8.2.0
Published Jun 02, 2021
Tracked Since Feb 18, 2026