Back

MEDIUM

python-pillow: Excessive looping in BLP image reader

Published Jun 2, 2021

Description

An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.

Affected products

Remediation

Red Hat mitigation

To mitigate this feature on Red Hat Quay keep the invoice generation feature disabled, as it is by default.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 2, 2021
Updated Aug 3, 2024
Reserved Mar 18, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 1, 2021
ENISA EUVD
Assigner mitre
Published Jun 2, 2021
Updated Aug 3, 2024
Exploited since n/a
EUVD-2021-0185 GHSA-HJFX-8P6C-G7GX