
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in Pillow before version 8.1.1, identified as CVE-2021-25291. The vulnerability exists in the TiffDecode.c file, specifically in the TiffreadRGBATile function, where an out-of-bounds read could occur due to invalid tile boundaries (Debian Tracker).
The vulnerability is present in the TiffDecode.c component of Pillow, where invalid tile boundaries could lead to an out-of-bounds read in TIFFReadRGBATile. The issue has been assigned a CVSS 3 Severity Score of 7.5 (High) (Ubuntu Security, Pillow Docs).
If a user or automated system were tricked into opening a specially-crafted Tiff file, a remote attacker could cause Pillow to crash, resulting in a denial of service, or possibly execute arbitrary code (Ubuntu Notice).
The vulnerability has been fixed in Pillow version 8.1.1 and later. Users are advised to update their Pillow installations to the latest version. For Ubuntu systems, standard system updates will make all the necessary changes to address this vulnerability (Ubuntu Notice, Pillow Docs).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."