Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-54033
HistoryMar 22, 2021 - 12:00 a.m.

Pillow Buffer Overflow Vulnerability (CNVD-2021-54033)

2021-03-2200:00:00
China National Vulnerability Database
www.cnvd.org.cn
19
pillow
buffer overflow
tiffdecode.c
version 8.1.1
image processing library
python-based

EPSS

0.002

Percentile

64.8%

Pillow is a Python-based image processing library. buffer overflow vulnerability exists in versions of Pillow prior to 8.1.1, which stems from the presence of a negative offset memcpy with an invalid size in TiffDecode.c. No details of the vulnerability are currently available.