High severity7.5NVD Advisory· Published Jun 2, 2021· Updated Jun 17, 2026
CVE-2021-28677
CVE-2021-28677
Description
An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pillowPyPI | < 8.2.0 | 8.2.0 |
Affected products
13- osv-coords10 versionspkg:rpm/opensuse/python-Pillow&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/python-Pillow&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/python-Pillow&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/python-Pillow&distro=SUSE%20OpenStack%20Cloud%208pkg:pypi/pillowpkg:rpm/suse/python-Pillow&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/almalinux/python3-pillowpkg:bitnami/pillowpkg:rpm/suse/python-Pillow&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/python-Pillow&distro=HPE%20Helion%20OpenStack%208
< 7.2.0-150300.3.12.1+ 9 more
- (no CPE)range: < 7.2.0-150300.3.12.1
- (no CPE)range: < 5.2.0-3.8.1
- (no CPE)range: < 5.2.0-3.8.1
- (no CPE)range: < 4.2.1-3.14.1
- (no CPE)range: < 8.2.0
- (no CPE)range: < 4.2.1-3.14.1
- (no CPE)range: < 5.1.1-16.el8
- (no CPE)range: < 8.2.0
- (no CPE)range: < 2.8.1-4.22.1
- (no CPE)range: < 4.2.1-3.14.1
- Pillow/Pillowdescription
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
10- github.com/python-pillow/Pillow/pull/5377nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-q5hq-fp76-qmrcghsaADVISORY
- lists.debian.org/debian-lts-announce/2021/07/msg00018.htmlnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-28677ghsaADVISORY
- pillow.readthedocs.io/en/stable/releasenotes/8.2.0.htmlnvdThird Party AdvisoryWEB
- security.gentoo.org/glsa/202107-33nvdThird Party AdvisoryWEB
- github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2021-93.yamlghsaWEB
- github.com/python-pillow/Pillow/commit/5a5e6db0abf4e7a638fb1b3408c4e495a096cb92ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/MQHA5HAIBOYI3R6HDWCLAGFTIQP767FLghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MQHA5HAIBOYI3R6HDWCLAGFTIQP767FL/nvd
News mentions
0No linked articles in our index yet.