cbcvebase.
CVE-2020-11538
published 2020-06-25

CVE-2020-11538: In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than…

PriorityP342high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
2.51%
82.9th percentile
In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.

Affected

13 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianpillow< pillow 7.2.0-1 (bookworm)pillow 7.2.0-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
paloaltopan-os
pythonpillow<= 7.0.0
pythonpillow>= 0 < 7.2.0-17.2.0-1
pythonpillow>= 0 < 7.2.0-17.2.0-1
pythonpillow>= 0 < 7.2.0-17.2.0-1
pythonpillow>= 0 < 7.2.0-17.2.0-1
pythonpillow>= 0 < 7.1.07.1.0

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian8.1LOW
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.