CVE-2021-25290: High severity python imaging library (pillow) vulnerability
A flaw was found in python-pillow. In TiffDecode.c, there is a negative-offset memcpy with an invalid size which could lead to a system crash.
Other sources
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.
In TiffDecode.c, there is a negative-offset memcpy with an invalid size.
Reference: https://pillow.readthedocs.io/en/stable/releasenotes/8.1.1.html
— Red Hat
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-25290?
CVE-2021-25290 is a vulnerability found in python-pillow that allows for a negative-offset memcpy with an invalid size, leading to a potential system crash.
What is the severity of CVE-2021-25290?
CVE-2021-25290 has a severity rating of 7 out of 10, indicating a high severity.
Which software packages are affected by CVE-2021-25290?
The following software packages are affected by CVE-2021-25290: python-pillow versions up to and excluding 8.1.1-16.el8, python-pillow version 8.1.1, and pip package Pillow versions up to and excluding 8.1.1.
What is the remedy for CVE-2021-25290?
To remediate CVE-2021-25290, update python-pillow to version 8.1.1 or apply the appropriate patch provided by the vendor.
Where can I find more information about CVE-2021-25290?
You can find more information about CVE-2021-25290 at the following references: [CVE website](https://www.cve.org/CVERecord?id=CVE-2021-25290), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-25290), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1934685), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2021:4149).