MEDIUM
python-pillow: Excessive looping in BLP image reader
Published Jun 2, 2021
6.8
MEDIUMCVSS 4.0
EPSS 0.73%
Description
An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.
Affected products
No data.
Configuration 2
- 33
No data.
Red Hat Enterprise Linux 8
python-pillow-0:5.1.1-16.el8
Fixed · RHSA-2021:4149
Red Hat Enterprise Linux 7
python-pillow
Out of support scope
Red Hat Quay 3
quay/quay-rhel8
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | python-pillow-0:5.1.1-16.el8 | Fixed | RHSA-2021:4149 |
| Red Hat Enterprise Linux 7 | python-pillow | Out of support scope | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
To mitigate this feature on Red Hat Quay keep the invoice generation feature disabled, as it is by default.
Weaknesses (2)
References (13)
- https://access.redhat.com/security/cve/CVE-2021-28678 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1958263 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-0185 Advisory
- https://github.com/advisories/GHSA-hjfx-8p6c-g7gx Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2021-94.yaml
- https://github.com/python-pillow/Pillow/pull/5377 x_refsource_MISCPatchThird Party Advisory
- https://github.com/python-pillow/Pillow/pull/5377/commits/496245aa4365d0827390bd0b6fbd11287453b3a1
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MQHA5HAIBOYI3R6HDWCLAGFTIQP767FL/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MQHA5HAIBOYI3R6HDWCLAGFTIQP767FL
- https://nvd.nist.gov/vuln/detail/CVE-2021-28678
- https://pillow.readthedocs.io/en/stable/releasenotes/8.2.0.html#cve-2021-28678-fix-blp-dos x_refsource_MISCRelease NotesVendor Advisory
- https://security.gentoo.org/glsa/202107-33 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-28678
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 2, 2021
Updated Aug 3, 2024
Reserved Mar 18, 2021
Link CVE-2021-28678
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2021-0185 GHSA-HJFX-8P6C-G7GX Assigner mitre
Published Jun 2, 2021
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2021-0185