CVE-2021-27923: Input Validation
A flaw was found in python-pillow. Attackers can cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
Other sources
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
— MITRE
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2021-27923.
What is the severity rating of CVE-2021-27923?
CVE-2021-27923 has a severity rating of 7.5 (high).
How can this vulnerability be exploited?
This vulnerability can be exploited to cause a denial of service by consuming excessive memory.
Which software versions are affected by CVE-2021-27923?
Versions up to and including Pillow 8.1.1 are affected by CVE-2021-27923.
How can I fix CVE-2021-27923?
To fix CVE-2021-27923, update your Python Pillow package to version 8.1.2 or higher.