PT-2020-5162 · Python Imaging Library+3 · Pillow+3

·

CVE-2020-5311

·

Published

2020-01-02

·

Updated

2024-03-06

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Pillow versions prior to 6.2.2
Description The issue is related to a buffer overflow in the SGI RLE decoding process. This can potentially allow a remote attacker to cause a denial of service. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For versions prior to 6.2.2, update to version 6.2.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the libImaging/SgiRleDecode.c module until a patch is available. Avoid using the SGI RLE decoding function in the affected library until the issue is resolved.

Fix

DoS

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05773
BIT-PILLOW-2020-5311
CESA-2020_0580
CVE-2020-5311
DSA-4631-1
GHSA-R7RM-8J6H-R933
MGASA-2020-0088
PYSEC-2020-82
RHSA-2020:0566
RHSA-2020:0580
RHSA-2020_0580
SUSE-RU-2020:2161-1
USN-4272-1

Affected Products

Centos
Pillow
Red Hat
Ubuntu