CVE-2021-28676 | Pillow up to 8.1.x FLI Data FliDecode infinite loop (Nessus ID 236661 / WID-SEC-2022-1835)
A vulnerability has been found in Pillow up to 8.1.x and classified as problematic. This issue affects the function FliDecode of the component FLI Data Handler. Performing a manipulation results in infinite loop.
This vulnerability is known as CVE-2021-28676. Access to the local network is required for this attack. No exploit is available.
The affected component should be upgraded.