Related Vulnerabilities: CVE-2021-25291  

A security issue was found in python-pillow before version 8.1.1. In TiffDecode.c, invalid tile boundaries could lead to an out of bounds read in TiffReadRGBATile.

Severity Medium

Remote No

Type Information disclosure

Description

A security issue was found in python-pillow before version 8.1.1. In TiffDecode.c, invalid tile boundaries could lead to an out of bounds read in TiffReadRGBATile.

AVG-1635 python-pillow 8.1.0-1 Medium Vulnerable

AVG-1439 python2-pillow 6.2.1-3 Medium Vulnerable

https://pillow.readthedocs.io/en/stable/releasenotes/8.1.1.html
https://github.com/python-pillow/Pillow/commit/8b8076bdcb3815be0ef0d279651d8d1342b8ea61