CVE-2021-34552
CRITICAL
9.8
CVSS Severity Score
Vulnerability Description
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
Affected Platforms (CPE)
📦
Python
Pillow
>= 1.0 and <= 1.1.7📦
Python
Pillow
>= 1.2 and <= 8.2.0💻
Debian
Debian Linux
= 9.0💻
Fedoraproject
Fedora
= 33💻
Fedoraproject
