CVE-2021-25293: High severity python imaging library (pillow) vulnerability
Published Feb 28, 2021
·Updated
A flaw was found in python-pillow. There is an Out of Bounds Read in SGIRleDecode.c.
Other sources
An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c.
There is an Out of Bounds Read in SGIRleDecode.c, since pillow 4.3.0.
Reference: https://pillow.readthedocs.io/en/stable/releasenotes/8.1.1.html
— Red Hat
Affected Software
4 affected componentsFixes available
redhat/python-pillow<0:5.1.1-16.el8
0:5.1.1-16.el8
redhat/python-pillow<8.1.1
8.1.1
pip/Pillow>=4.3.0<8.1.1
8.1.1
Python Pillow<8.1.1
Event History
Feb 28, 2021
CVE Published
12:00 AM
Mar 19, 2021
CVE Published
via MITRE·03:30 AM
Data Sourced
via MITRE·03:30 AM
Description
Mar 29, 2021
Advisory Published
via GitHub·04:35 PM
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
1
What is the vulnerability ID for this issue in python-pillow?
The vulnerability ID for this issue in python-pillow is CVE-2021-25293.
2
What is the severity of CVE-2021-25293?
The severity of CVE-2021-25293 is high (7.5).
3
What is the description of CVE-2021-25293?
CVE-2021-25293 is a flaw in python-pillow that allows for an out-of-bounds read.
4
What is the affected software for CVE-2021-25293?
The affected software for CVE-2021-25293 is python-pillow versions up to 8.1.1.
5
How do I fix CVE-2021-25293?
To fix CVE-2021-25293, upgrade python-pillow to version 8.1.1 or later.