CVE-2021-27921 log
| Source | 
 | 
| Severity | Low | 
| Remote | No | 
| Type | Denial of service | 
| Description | Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large. | 
| Group | Package | Affected | Fixed | Severity | Status | Ticket | 
|---|---|---|---|---|---|---|
| AVG-1439 | python2-pillow | 6.2.1-3 | Medium | Unknown | ||
| AVG-1635 | python-pillow | 8.1.0-1 | 8.1.2-1 | Medium | Fixed | FS#70044 | 
| References | 
|---|
| https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html https://github.com/python-pillow/Pillow/commit/756fff33128a0b643d10518a26ad04b726dd8973 |