In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-py3-pillow | Aug 22, 2024 | Jan 12, 2021 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Jan 12, 2021 | |
| Debian | debian-upgrade-pillow | Jul 30, 2024 | Jan 12, 2021 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-python-pillow | Jan 12, 2021 | Jan 11, 2021 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-library-python-pillow-27-5-1-0-11-4-31-0-1-88-5oracle-solaris-11-4-upgrade-library-python-pillow-37-8-1-0-11-4-31-0-1-88-5oracle-solaris-11-4-upgrade-library-python-pillow-39-8-1-0-11-4-31-0-1-88-5oracle-solaris-11-4-upgrade-library-python-pillow-8-1-0-11-4-31-0-1-88-5 | Mar 17, 2021 | Jan 12, 2021 | |
| Suse | — | suse-upgrade-python3-cairosvgsuse-upgrade-python3-pillowsuse-upgrade-python3-pillow-tk | Aug 11, 2021 | Jan 12, 2021 |
| Ubuntu | ubuntu-upgrade-python-pilubuntu-upgrade-python3-pil | Jan 19, 2021 | Jan 12, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub