Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2021-34552
Description:Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
Test IDs: 1.3.6.1.4.1.25623.1.0.892716   1.3.6.1.4.1.25623.1.0.879906   1.3.6.1.4.1.25623.1.0.854051   1.3.6.1.4.1.25623.1.0.879910   1.3.6.1.4.1.25623.1.1.2.2021.2518   1.3.6.1.4.1.25623.1.0.879914   1.3.6.1.4.1.25623.1.0.879912   1.3.6.1.4.1.25623.1.0.879895  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2021-34552
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VUGBBT63VL7G4JNOEIPDJIOC34ZFBKNJ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7V6LCG525ARIX6LX5QRYNAWVDD2MD2SV/
https://security.gentoo.org/glsa/202211-10
https://pillow.readthedocs.io/en/stable/releasenotes/8.3.0.html#buffer-overflow
https://pillow.readthedocs.io/en/stable/releasenotes/index.html
https://lists.debian.org/debian-lts-announce/2021/07/msg00018.html




© 1998-2025 E-Soft Inc. All rights reserved.