cbcvebase.
CVE-2020-11538
published 2020-06-25

CVE-2020-11538: In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than…

high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.

Affected

13 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianpillow< pillow 7.2.0-1 (bookworm)pillow 7.2.0-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
paloaltopan-os
pythonpillow<= 7.0.0
pythonpillow>= 0 < 7.2.0-17.2.0-1
pythonpillow>= 0 < 7.2.0-17.2.0-1
pythonpillow>= 0 < 7.2.0-17.2.0-1
pythonpillow>= 0 < 7.2.0-17.2.0-1
pythonpillow>= 0 < 7.1.07.1.0

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa9.8CRITICAL
osv9.8CRITICAL