CVE-2021-34552: Buffer Overflow
A flaw was found in python-pillow. This flaw allows an attacker to pass controlled parameters directly into a convert function, triggering a buffer overflow in the "convert()" or "ImagingConvertTransparent()" functions in Convert.c. The highest threat to this vulnerability is to system availability. In Red Hat Quay, a vulnerable version of python-pillow is shipped with quay-registry-container, however the invoice generation feature which uses python-pillow is disabled by default. Therefore impact has been rated Moderate.
Other sources
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this flaw in python-pillow?
The vulnerability ID for this flaw in python-pillow is CVE-2021-34552.
What is the severity rating of CVE-2021-34552?
The severity rating of CVE-2021-34552 is medium with a score of 5.9.
Which functions in python-pillow are affected by CVE-2021-34552?
The "convert()" and "ImagingConvertTransparent()" functions in Convert.c are affected by CVE-2021-34552.
What is the impacted software due to CVE-2021-34552?
The impacted software is python-pillow versions 0:5.1.1-16.el8 and versions up to, but excluding, 8.3.0.
Where can I find more information about CVE-2021-34552?
You can find more information about CVE-2021-34552 at the following references: [CVE-2021-34552](https://www.cve.org/CVERecord?id=CVE-2021-34552), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-34552), [Pillow Release Notes](https://pillow.readthedocs.io/en/stable/releasenotes/8.3.0.html#buffer-overflow), [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1982378), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2021:4149).