First published: Sun Feb 28 2021(Updated: )
A flaw was found in python-pillow. Invalid tile boundaries could lead to an OOB Read in TiffReadRGBATile in TiffDecode.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Python Pillow | <8.1.1 | |
pip/Pillow | <8.2.0 | 8.2.0 |
Disable the invoice generation feature to mitigate this vulnerability in Red Hat Quay.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-25291.
The severity of CVE-2021-25291 is high (7.5).
The affected software for CVE-2021-25291 is Python Pillow version up to 8.2.0.
To fix CVE-2021-25291, update Python Pillow to version 8.2.0 or above.
You can find more information about CVE-2021-25291 at the following references: - [CVE Website](https://www.cve.org/CVERecord?id=CVE-2021-25291) - [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-25291) - [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1934692) - [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2021:3917)