mirror of
				https://github.com/python-pillow/Pillow.git
				synced 2025-10-31 16:07:30 +03:00 
			
		
		
		
	
		
			
				
	
	
		
			13 lines
		
	
	
		
			444 B
		
	
	
	
		
			ReStructuredText
		
	
	
	
	
	
			
		
		
	
	
			13 lines
		
	
	
		
			444 B
		
	
	
	
		
			ReStructuredText
		
	
	
	
	
	
| 8.1.2
 | |
| -----
 | |
| 
 | |
| Security
 | |
| ========
 | |
| 
 | |
| There is an exhaustion of memory DOS in the BLP (:cve:`2021-27921`),
 | |
| ICNS (:cve:`2021-27922`) and ICO (:cve:`2021-27923`) container formats
 | |
| where Pillow did not properly check the reported size of the contained image.
 | |
| These images could cause arbitrarily large memory allocations. This was reported
 | |
| by Jiayi Lin, Luke Shaffer, Xinran Xie, and Akshay Ajayan of
 | |
| `Arizona State University <https://www.asu.edu/>`_.
 |