An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.
2021-06-02T16:15:08.860
2024-11-21T06:00:06.830
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | python | pillow | < 8.2.0 | Yes |
Operating System | fedoraproject | fedora | 33 | Yes |