CVE-2021-34552
CRITICAL
9.8
CVSS Severity Score
Vulnerability Description
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
Affected Platforms (CPE)
π¦
Python
Pillow
>= 1.0 and <= 1.1.7π¦
Python
Pillow
>= 1.2 and <= 8.2.0π»
Debian
Debian Linux
= 9.0π»
Fedoraproject
Fedora
= 33π»
Fedoraproject
