Skip to content

Latest commit

 

History

History
33 lines (22 loc) · 1.13 KB

8.1.2.rst

File metadata and controls

33 lines (22 loc) · 1.13 KB

8.1.2

Security

Fix CVE-2021-27921

Note

More information about this vulnerability included in database record 2021-27921

There is an exhaustion of memory DOS in BLP images. where Pillow did not properly check the reported size of the contained image. These images could cause arbitrarily large memory allocations.

Fix CVE-2021-27922

Note

More information about this vulnerability included in database record 2021-27921

There is an exhaustion of memory DOS in ICNS images where Pillow did not properly check the reported size of the contained image. These images could cause arbitrarily large memory allocations.

Fix CVE-2021-27923

Note

More information about this vulnerability included in database record 2021-27923

There is an exhaustion of memory DOS in ICO images where Pillow did not properly check the reported size of the contained image. These images could cause arbitrarily large memory allocations.

These were reported by Jiayi Lin, Luke Shaffer, Xinran Xie and Akshay Ajayan of Arizona State University.