CVE-2021-27922

Related Vulnerabilities: CVE-2021-27922  

Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.

Description

The MITRE CVE dictionary describes this issue as:

Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.

Additional Information

  • Bugzilla 1935396: CVE-2021-27922 python-pillow: reported size of a contained image is not properly checked for an ICNS container
  • CWE-20->CWE-400: Improper Input Validation leads to Uncontrolled Resource Consumption
  • FAQ: Frequently asked questions about CVE-2021-27922