Security Advisory

CVE-2021-28677

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-06-02 15:18:49
Last updated 2024-08-03 21:47:33
Assigner mitre
State PUBLISHED

Description

An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of r and n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.