CVE-2021-34552

CRITICAL

Python Pillow < 1.1.7 - Buffer Overflow

Title source: rule
STIX 2.1

Description

Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.

Scores

CVSS v3 9.8
EPSS 0.0034
EPSS Percentile 56.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (5)
debian/debian_linux 9.0
fedoraproject/fedora 33
fedoraproject/fedora 34
pypi/pillow 0 - 8.3.0PyPI
python/pillow 1.0 - 1.1.7
Published Jul 13, 2021
Tracked Since Feb 18, 2026