Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-54035
HistoryMar 15, 2021 - 12:00 a.m.

Pillow Buffer Overflow Vulnerability (CNVD-2021-54035)

2021-03-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
14

0.002 Low

EPSS

Percentile

64.8%

Pillow is a Python-based image processing library.A buffer overflow vulnerability exists in Pillow Tiff image file processing, which can be exploited by remote attackers to submit special file requests that trick users into parsing, which can crash the application or execute arbitrary code in the application context.

CPENameOperatorVersion
pillow pillowlt8.1.1