CyberSec.Space Logo
CVEブラウザに戻る

CVE-2021-25289

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0960%
EPSS Percentile25.97th
Published2021年3月19日
Last Modified2024年11月21日

Vulnerability Description

An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for CVE-2020-35654.

Affected Platforms (CPE)

📦
Python

Pillow

< 8.1.1

References & Advisories

関連する脆弱性情報