First published: Sun Feb 28 2021(Updated: )
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/python-pillow | <0:5.1.1-16.el8 | 0:5.1.1-16.el8 |
Python Pillow | <8.1.1 | |
Debian Debian Linux | =9.0 | |
redhat/python-pillow | <8.1.1 | 8.1.1 |
pip/pillow | >=0<8.1.1 | 8.1.1 |
Disable the invoice generation feature to mitigate this vulnerability in Red Hat Quay.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25290 is a vulnerability found in python-pillow that allows for a negative-offset memcpy with an invalid size, leading to a potential system crash.
CVE-2021-25290 has a severity rating of 7 out of 10, indicating a high severity.
The following software packages are affected by CVE-2021-25290: python-pillow versions up to and excluding 8.1.1-16.el8, python-pillow version 8.1.1, and pip package Pillow versions up to and excluding 8.1.1.
To remediate CVE-2021-25290, update python-pillow to version 8.1.1 or apply the appropriate patch provided by the vendor.
You can find more information about CVE-2021-25290 at the following references: [CVE website](https://www.cve.org/CVERecord?id=CVE-2021-25290), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-25290), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1934685), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2021:4149).