
Cloud Vulnerability DB
A community-led vulnerabilities database
An out-of-bounds read vulnerability (CVE-2021-25287) was discovered in Pillow before version 8.2.0. The vulnerability specifically affects the J2kDecode functionality in the j2ku_graya_la component. This security issue was identified and disclosed in early 2021, affecting the Python Imaging Library (Pillow) software (MITRE CVE, NVD).
The vulnerability occurs in the JPEG2000 decoder implementation where for J2k images with multiple bands, it's legal to have different widths for each band (e.g., 1 byte for L, 4 bytes for A). The issue dates back to Pillow 2.4.0 and could lead to an out-of-bounds read condition. The vulnerability has been assigned a CVSS v3.1 base score of 9.1 (Critical) with attack vector: Network, attack complexity: Low, privileges required: None, user interaction: None, scope: Unchanged, confidentiality: High, integrity: None, and availability: High (Ubuntu Security).
The vulnerability could potentially lead to unauthorized access to memory contents and denial of service conditions. When exploited, the out-of-bounds read vulnerability could allow attackers to read sensitive information from memory locations that should be inaccessible, potentially exposing confidential data (NVD).
The vulnerability is remotely exploitable and requires no user interaction or special privileges. It can be triggered through specially crafted JPEG2000 images with specific band configurations (Ubuntu Security).
The vulnerability has been fixed in Pillow version 8.2.0. Users are advised to upgrade to this version or later. Multiple Linux distributions have released security updates to address this vulnerability, including Ubuntu, Fedora, and Gentoo. For systems that cannot be immediately updated, there are no known workarounds (Gentoo Security, Pillow Docs).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."