Related Vulnerabilities: CVE-2021-27922  

Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.

Severity Low

Remote No

Type Denial of service

Description

Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.

AVG-1635 python-pillow 8.1.0-1 Medium Vulnerable

AVG-1439 python2-pillow 6.2.1-3 Medium Vulnerable

https://pillow.readthedocs.io/en/stable/releasenotes/8.1.1.html