Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-27923
HistoryMar 03, 2021 - 9:15 a.m.

Design/Logic Flaw

2021-03-0309:15:00
PRIOn knowledge base
www.prio-n.com
2

8 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

64.6%

Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.

CPENameOperatorVersion
fedoraeq32
fedoraeq33
fedoraeq34
pillowlt8.1.1