QID 355121

Date Published: 2023-05-29

QID 355121: Amazon Linux Security Advisory for python-pillow : ALAS2023-2023-146

an issue was discovered in pillow before 8.1.1.
In tiffdecode.c, there is a negative-offset memcpy with an invalid size. (
( CVE-2021-25290) an issue was discovered in pillow before 8.1.1.
In tiffdecode.c, there is an out-of-bounds read in tiffreadrgbatile via invalid tile boundaries. (
( CVE-2021-25291) an issue was discovered in pillow before 8.1.1.
There is an out-of-bounds read in sgirledecode.c. (
( CVE-2021-25293) pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a blp container, and thus an attempted memory allocation can be very large. (
( CVE-2021-27921) pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an icns container, and thus an attempted memory allocation can be very large. (
( CVE-2021-27922) pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ico container, and thus an attempted memory allocation can be very large. (
( CVE-2021-27923) an issue was discovered in pillow before 8.2.0.
For fli data, flidecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load. (

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Please refer to Amazon advisory: ALAS2023-2023-146 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ALAS2023-2023-146 amazon linux 2023 URL Logo alas.aws.amazon.com/AL2023/ALAS-2023-146.html