First published: Thu Apr 01 2021(Updated: )
An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/python-pillow | <0:5.1.1-16.el8 | 0:5.1.1-16.el8 |
Python Pillow | <8.2.0 | |
Fedoraproject Fedora | =33 | |
redhat/python-pillow | <8.2.0 | 8.2.0 |
pip/Pillow | >=2.4.0<8.2.0 | 8.2.0 |
To mitigate this feature on Red Hat Quay keep the invoice generation feature disabled as it is by default.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-25287.
The severity of CVE-2021-25287 is critical with a CVSS score of 9.1.
The affected software includes Python Pillow versions up to and excluding 8.2.0, and Python Pillow version 0:5.1.1-16.el8 on Red Hat Enterprise Linux 8.
To fix CVE-2021-25287, you should update to version 8.2.0 of Python Pillow.
You can find more information about CVE-2021-25287 on the following references: [https://pillow.readthedocs.io/en/stable/releasenotes/8.2.0.html#security](https://pillow.readthedocs.io/en/stable/releasenotes/8.2.0.html#security), [https://github.com/python-pillow/Pillow/pull/5377](https://github.com/python-pillow/Pillow/pull/5377), [https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1958230](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1958230).