CVE-2021-25291: High severity python imaging library (pillow) vulnerability
A flaw was found in python-pillow. Invalid tile boundaries could lead to an OOB Read in TiffReadRGBATile in TiffDecode.c.
Other sources
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.
An issue was discovered in Pillow before 8.2.0. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.
— GitHub
Invalid tile boundaries could lead to an OOB Read in TiffReadRGBATile in In TiffDecode.c.
Reference: https://pillow.readthedocs.io/en/stable/releasenotes/8.1.1.html
— Red Hat
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-25291.
What is the severity of CVE-2021-25291?
The severity of CVE-2021-25291 is high (7.5).
What is the affected software for CVE-2021-25291?
The affected software for CVE-2021-25291 is Python Pillow version up to 8.2.0.
How can I fix CVE-2021-25291?
To fix CVE-2021-25291, update Python Pillow to version 8.2.0 or above.
Where can I find more information about CVE-2021-25291?
You can find more information about CVE-2021-25291 at the following references: - [CVE Website](https://www.cve.org/CVERecord?id=CVE-2021-25291) - [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-25291) - [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1934692) - [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2021:3917)