CVE-2021-27921: Input Validation
A flaw was found in python-pillow. Attackers can cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
Other sources
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
— NVD
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-27921?
CVE-2021-27921 is a vulnerability in python-pillow that allows attackers to cause a denial of service by consuming excessive memory.
What is the severity of CVE-2021-27921?
The severity of CVE-2021-27921 is rated as high (7.5).
How does CVE-2021-27921 impact Pillow?
CVE-2021-27921 allows attackers to cause a denial of service in Pillow by consuming excessive memory.
How can I fix CVE-2021-27921?
To fix CVE-2021-27921, update python-pillow to version 8.1.1 or higher.
Where can I find more information about CVE-2021-27921?
More information about CVE-2021-27921 can be found on the CVE website (https://www.cve.org/CVERecord?id=CVE-2021-27921) and the NVD website (https://nvd.nist.gov/vuln/detail/CVE-2021-27921).