GHSA-mvg9-xffr-p774
Dashboard / Vulnerabilities / GHSA-mvg9-xffr-p774
GHSA-mvg9-xffr-p774
Summary: Out of bounds read in Pillow
Details: An issue was discovered in Pillow before 8.2.0. In `TiffDecode.c`, there is an out-of-bounds read in `TiffreadRGBATile` via invalid tile boundaries.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-25291, https://github.com/python-pillow/Pillow/commit/8b8076bdcb3815be0ef0d279651d8d1342b8ea61, https://github.com/python-pillow/Pillow/commit/cbdce6c5d054fccaf4af34b47f212355c64ace7a, https://github.com/advisories/GHSA-mvg9-xffr-p774, https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2021-37.yaml, https://github.com/python-pillow/Pillow, https://pillow.readthedocs.io/en/stable/releasenotes/8.1.1.html, https://security.gentoo.org/glsa/202107-33
Affected packages
Package
Name: pillow
Purl: pkg:pypi/pillow
Affected ranges
Type: ECOSYSTEM
Events:
