CVE-2021-28678

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
02/06/2021
Last modified:
07/11/2023

Description

An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:* 8.2.0 (excluding)
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*