CyberSec.Space Logo
Back to CVE Browser

CVE-2021-25289

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0960%
EPSS Percentile25.97th
PublishedMar 19, 2021
Last ModifiedNov 21, 2024

Vulnerability Description

An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for CVE-2020-35654.

Affected Platforms (CPE)

πŸ“¦
Python

Pillow

< 8.1.1

References & Advisories

Related Vulnerabilities