QID 198292

Date Published: 2021-03-25

QID 198292: Ubuntu Security Notification for Pillow Vulnerabilities (USN-4763-1)

It was discovered that Pillow incorrectly handled certain Tiff image files.

It was discovered that Pillow incorrectly handled certain Tiff image files.

It was discovered that Pillow incorrectly handled certain PDF files.

It was discovered that Pillow incorrectly handled certain SGI image files.

It was discovered that Pillow incorrectly handled certain BLP files.

It was discovered that Pillow incorrectly handled certain ICNS files.

It was discovered that Pillow incorrectly handled certain ICO files.

If a user or automated system were tricked into opening a specially-crafted Tiff file, a remote attacker could cause Pillow to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2021-25289, CVE-2021-25291)

If a user or automated system were tricked into opening a specially-crafted Tiff file, a remote attacker could cause Pillow to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-25290)

If a user or automated system were tricked into opening a specially-crafted PDF file, a remote attacker could cause Pillow to hang, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 20.10. (CVE-2021-25292)

If a user or automated system were tricked into opening a specially-crafted SGI file, a remote attacker could possibly cause Pillow to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 20.10. (CVE-2021-25293)

If a user or automated system were tricked into opening a specially-crafted BLP file, a remote attacker could possibly cause Pillow to consume resources, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 20.10. (CVE-2021-27921)

If a user or automated system were tricked into opening a specially-crafted ICNS file, a remote attacker could possibly cause Pillow to consume resources, resulting in a denial of service. (CVE-2021-27922)

If a user or automated system were tricked into opening a specially-crafted ICO file, a remote attacker could possibly cause Pillow to consume resources, resulting in a denial of service. (CVE-2021-27922)

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Ubuntu advisory USN-4763-1 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-4763-1 16.04 (Xenial) on src python-pil URL Logo launchpad.net/ubuntu/+source/pillow/3.1.2-0ubuntu1.6
    USN-4763-1 16.04 (Xenial) on src python3-pil URL Logo launchpad.net/ubuntu/+source/pillow/3.1.2-0ubuntu1.6
    USN-4763-1 18.04 (bionic) on src python-pil URL Logo launchpad.net/ubuntu/+source/pillow/5.1.0-1ubuntu0.5
    USN-4763-1 18.04 (bionic) on src python3-pil URL Logo launchpad.net/ubuntu/+source/pillow/5.1.0-1ubuntu0.5
    USN-4763-1 20.04 (focal) on src python3-pil URL Logo launchpad.net/ubuntu/+source/pillow/7.0.0-4ubuntu0.3
    USN-4763-1 20.10 (groovy) on src python3-pil URL Logo launchpad.net/ubuntu/+source/pillow/7.2.0-1ubuntu0.2