570
VMScore

CVE-2021-25288

Published: 02/06/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

An issue exists in Pillow prior to 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

python pillow

fedoraproject fedora 33

Vendor Advisories

Debian Bug report logs - #989062 CVE-2021-25287 CVE-2021-25288 CVE-2021-28675 CVE-2021-28676 CVE-2021-28677 CVE-2021-28678 Package: src:pillow; Maintainer for src:pillow is Matthias Klose <doko@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 24 May 2021 20:57:04 UTC Severity: important Tags: ...