CVE-2021-28675

Name
CVE-2021-28675
Description
An issue was discovered in Pillow before 8.2.0. PSDImagePlugin.PsdImageFile lacked a sanity check on the number of input layers relative to the size of the data block. This could lead to a DoS on Image.open prior to Image.load.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://pillow.readthedocs.io/en/stable/releasenotes/8.2.0.html#cve-2021-28675-fix-dos-in-psdimageplugin
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MQHA5HAIBOYI3R6HDWCLAGFTIQP767FL/
Third Party Advisory https://security.gentoo.org/glsa/202107-33

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:* pillow >= None < 8.2.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
py3-pillow edge-main 8.2.0-r0 None fixed
py3-pillow edge-community 8.2.0-r0 None fixed
py3-pillow 3.22-community 8.2.0-r0 None fixed
py3-pillow 3.21-community 8.2.0-r0 None fixed
py3-pillow 3.20-community 8.2.0-r0 None fixed
py3-pillow 3.19-community 8.2.0-r0 None fixed
py3-pillow 3.18-community 8.2.0-r0 None fixed
py3-pillow 3.17-community 8.2.0-r0 None fixed