CRITICAL 9.8 PyPI

Buffer Overflow in Pillow

GHSA-7534-mm45-c74v · BIT-pillow-2021-34552 · CVE-2021-34552 · PYSEC-2021-331

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.

Ready to move

Start Securing

Free, no credit card | First findings in minutes