First published: Thu Apr 01 2021(Updated: )
An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/Pillow | <8.2.0 | 8.2.0 |
Python Pillow | <8.2.0 | |
Fedoraproject Fedora | =33 | |
redhat/python-pillow | <8.2.0 | 8.2.0 |
redhat/python-pillow | <0:5.1.1-16.el8 | 0:5.1.1-16.el8 |
To mitigate this feature on Red Hat Quay, keep the invoice generation feature disabled, as it is by default.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28676 is a vulnerability in Pillow before version 8.2.0 that could lead to an infinite loop on load, potentially impacting system availability.
CVE-2021-28676 can affect system availability by causing an infinite loop on load.
CVE-2021-28676 is classified as a high severity vulnerability with a severity value of 7.
Python Pillow versions before 8.2.0, specifically version 0:5.1.1-16.el8, are affected by CVE-2021-28676.
To fix CVE-2021-28676, upgrade to version 8.2.0 of Python Pillow, which includes the necessary security patches.