PT-2020-12212 · Psd Tools · Psd-Tools
Kyamagu
·
Published
2020-03-14
·
Updated
2020-03-19
·
CVE-2020-10571
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
psd-tools versions prior to 1.9.4
Description
An issue was discovered in the Cython implementation of RLE decoding, which did not check for malicious or malformed PSD input data during decoding to the PIL.Image or NumPy format, leading to a Buffer Overflow.
Recommendations
For versions prior to 1.9.4, upgrade to version 1.9.4 to resolve the issue.
As a temporary workaround for already installed psd-tools with the Cython extension, consider upgrading to version 1.9.4, as without Cython present on installation, the buffer overflow does not occur, but an IndexError will be thrown.
Fix
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Psd-Tools