Insufficient data authenticity validation In pillow
Description
Insufficient Verification of Data Authenticity in Pillow An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 8.2.0 | ||
alpine v3.14 | 8.2.0-r0 | ||
debian 14 | 8.1.2+dfsg-0.2 | ||
debian 13 | 8.1.2+dfsg-0.2 | ||
alpine v3.15 | 8.2.0-r0 | ||
debian 11 | 8.1.2+dfsg-0.2 | ||
debian 12 | 8.1.2+dfsg-0.2 | ||
rpm rhel7 | - | - | |
rpm rhel8 | 0:5.1.1-16.el8 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.
References
1. 2. 3. 4. 5.