vulnerability
Oracle Solaris 11: CVE-2021-34552 (11.4 SRU 37.101.1)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:P/I:P/A:P) | Jul 13, 2021 | Oct 12, 2021 | Feb 17, 2022 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Jul 13, 2021
Added
Oct 12, 2021
Modified
Feb 17, 2022
Description
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
Solutions
oracle-solaris-11-4-upgrade-library-python-pillow-27-5-1-0-11-4-37-0-1-101-1oracle-solaris-11-4-upgrade-library-python-pillow-37-8-2-0-11-4-37-0-1-101-1oracle-solaris-11-4-upgrade-library-python-pillow-39-8-2-0-11-4-37-0-1-101-1oracle-solaris-11-4-upgrade-library-python-pillow-8-2-0-11-4-37-0-1-101-1
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.