CVE-2021-25287: Critical severity python imaging library (pillow) vulnerability
An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2kugrayala.
Other sources
There is an out-of-bounds read in J2kDecode in j2kugrayala. For J2k images with multiple bands, it’s legal to have different widths for each band, e.g. 1 byte for L, 4 bytes for A.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-25287.
What is the severity of CVE-2021-25287?
The severity of CVE-2021-25287 is critical with a CVSS score of 9.1.
What is the affected software?
The affected software includes Python Pillow versions up to and excluding 8.2.0, and Python Pillow version 0:5.1.1-16.el8 on Red Hat Enterprise Linux 8.
How can I fix CVE-2021-25287?
To fix CVE-2021-25287, you should update to version 8.2.0 of Python Pillow.
Where can I find more information about CVE-2021-25287?
You can find more information about CVE-2021-25287 on the following references: [https://pillow.readthedocs.io/en/stable/releasenotes/8.2.0.html#security](https://pillow.readthedocs.io/en/stable/releasenotes/8.2.0.html#security), [https://github.com/python-pillow/Pillow/pull/5377](https://github.com/python-pillow/Pillow/pull/5377), [https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1958230](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1958230).