CVE-2021-28677

CVE-2021-28677

An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of r and n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.

Source: CVE-2021-28677

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다