CVE-2021-27923

Related Vulnerabilities: CVE-2021-27923  

Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.

Description

The MITRE CVE dictionary describes this issue as:

Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.

Additional Information

  • Bugzilla 1935401: CVE-2021-27923 python-pillow: reported size of a contained image is not properly checked for an ICO container
  • CWE-20->CWE-400: Improper Input Validation leads to Uncontrolled Resource Consumption
  • FAQ: Frequently asked questions about CVE-2021-27923