In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-pillow | Aug 22, 2024 | Jan 12, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 12, 2021 |
| Debian | — | Upgrade pillow | Jul 30, 2024 | Jan 12, 2021 |
| Gentoo Linux | — | Upgrade dev-python/pillow. | Jan 12, 2021 | Jan 11, 2021 |
| Oracle Solaris | — | Upgrade library/python/pillow to version 8.1.0-11.4.31.0.1.88.5 on Solaris 11.4Upgrade library/python/pillow-39 to version 8.1.0-11.4.31.0.1.88.5 on Solaris 11.4Upgrade library/python/pillow-37 to version 8.1.0-11.4.31.0.1.88.5 on Solaris 11.4Upgrade library/python/pillow-27 to version 5.1.0-11.4.31.0.1.88.5 on Solaris 11.4 | Mar 17, 2021 | Jan 12, 2021 |
| Suse | — | Upgrade python3-cairosvgUpgrade python3-pillow-tkUpgrade python3-pillow | Aug 11, 2021 | Jan 12, 2021 |
| Ubuntu | — | Upgrade python-pilUpgrade python3-pil | Jan 19, 2021 | Jan 12, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub