PT-2020-12212 · Psd Tools · Psd-Tools

Kyamagu

·

Published

2020-03-14

·

Updated

2020-03-19

·

CVE-2020-10571

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions psd-tools versions prior to 1.9.4
Description An issue was discovered in the Cython implementation of RLE decoding, which did not check for malicious or malformed PSD input data during decoding to the PIL.Image or NumPy format, leading to a Buffer Overflow.
Recommendations For versions prior to 1.9.4, upgrade to version 1.9.4 to resolve the issue. As a temporary workaround for already installed psd-tools with the Cython extension, consider upgrading to version 1.9.4, as without Cython present on installation, the buffer overflow does not occur, but an IndexError will be thrown.

Fix

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10571
GHSA-22JR-VC7J-G762
PYSEC-2020-91

Affected Products

Psd-Tools