PT-2020-12478 · Pillow+2 · Pillow+2

Hugovk

·

Published

2020-06-25

·

Updated

2024-03-06

·

CVE-2020-10994

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Pillow versions prior to 7.1.0
Description The issue is related to multiple out-of-bounds reads that can occur via a crafted JP2 file in the libImaging/Jpeg2KDecode.c module.
Recommendations For Pillow versions prior to 7.1.0, update to version 7.1.0 or later to resolve the issue.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BIT-PILLOW-2020-10994
CVE-2020-10994
GHSA-VJ42-XQ3R-HR3R
MGASA-2020-0434
PYSEC-2020-79
SUSE-RU-2020:2161-1
SUSE-SU-2020:2057-1
SUSE-SU-2020:2911-1
SUSE-SU-2020:3309-1
USN-4430-1
USN-4430-2

Affected Products

Linuxmint
Pillow
Ubuntu