CVE-2020-35654
published 2021-01-12CVE-2020-35654: In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.79%
75.9th percentile
In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pillow | < pillow 8.1.0-1 (bookworm) | pillow 8.1.0-1 (bookworm) |
| debian | pillow | < pillow 8.1.1-1 (bookworm) | pillow 8.1.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| paloalto | pan-os | — | — |
| python | pillow | < 8.1.0 | 8.1.0 |
| python | pillow | < 8.1.1 | 8.1.1 |
| python | pillow | >= 0 < 8.1.0-1 | 8.1.0-1 |
| python | pillow | >= 0 < 8.1.1-1 | 8.1.1-1 |
| python | pillow | >= 0 < 8.1.0-1 | 8.1.0-1 |
| python | pillow | >= 0 < 8.1.1-1 | 8.1.1-1 |
| python | pillow | >= 0 < 8.1.0-1 | 8.1.0-1 |
| python | pillow | >= 0 < 8.1.1-1 | 8.1.1-1 |
| python | pillow | >= 0 < 8.1.0-1 | 8.1.0-1 |
| python | pillow | >= 0 < 8.1.1-1 | 8.1.1-1 |
| python | pillow | >= 0 < 8.1.0 | 8.1.0 |
| python | pillow | >= 0 < 8.1.1 | 8.1.1 |
| python | pillow | >= 0 < 3.1.2-0ubuntu1.5 | 3.1.2-0ubuntu1.5 |
| python | pillow | >= 0 < 5.1.0-1ubuntu0.4 | 5.1.0-1ubuntu0.4 |
| python | pillow | >= 0 < 7.0.0-4ubuntu0.2 | 7.0.0-4ubuntu0.2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa8.8HIGH
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Out of bounds write in Pillow
osv·2021-03-29·CVSS 8.8
CVE-2021-25289 [HIGH] Out of bounds write in Pillow
Out of bounds write in Pillow
An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for CVE-2020-35654.
GHSA
Out of bounds write in Pillow
ghsa·2021-03-29·CVSS 8.8
CVE-2021-25289 [HIGH] CWE-787 Out of bounds write in Pillow
Out of bounds write in Pillow
An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for CVE-2020-35654.
OSV
CVE-2021-25289: An issue was discovered in Pillow before 8
osv·2021-03-19·CVSS 8.8
CVE-2021-25289 [HIGH] CVE-2021-25289: An issue was discovered in Pillow before 8
An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for CVE-2020-35654.
OSV
Pillow Out-of-bounds Write
osv·2021-03-18
CVE-2020-35654 [HIGH] Pillow Out-of-bounds Write
Pillow Out-of-bounds Write
In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.
GHSA
Pillow Out-of-bounds Write
ghsa·2021-03-18
CVE-2020-35654 [HIGH] CWE-787 Pillow Out-of-bounds Write
Pillow Out-of-bounds Write
In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.
OSV
pillow vulnerabilities
osv·2021-01-18·CVSS 7.1
CVE-2020-35653 [HIGH] pillow vulnerabilities
pillow vulnerabilities
It was discovered that Pillow incorrectly handled certain PCX image files.
If a user or automated system were tricked into opening a specially-crafted
PCX file, a remote attacker could possibly cause Pillow to crash,
resulting in a denial of service. (CVE-2020-35653)
It was discovered that Pillow incorrectly handled certain Tiff image files.
If a user or automated system were tricked into opening a specially-crafted
Tiff file, a remote attacker could cause Pillow to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2020-35654)
It was discovered that Pillow incorrectly handled certain SGI image files.
If a user or automated system were tricked into opening a specially-crafte
OSV
CVE-2020-35654: In Pillow before 8
osv·2021-01-12·CVSS 8.8
CVE-2020-35654 [HIGH] CVE-2020-35654: In Pillow before 8
In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Red Hat
python-pillow: insufficent fix for CVE-2020-35654 due to incorrect error checking in TiffDecode.c
vendor_redhat·2021-02-28·CVSS 8.8
CVE-2021-25289 [HIGH] CWE-120 python-pillow: insufficent fix for CVE-2020-35654 due to incorrect error checking in TiffDecode.c
python-pillow: insufficent fix for CVE-2020-35654 due to incorrect error checking in TiffDecode.c
An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for CVE-2020-35654.
A flaw was found in python-pillow. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. The previous fix for CVE-2020-35654 was insufficient due to incorrect error checking in TiffDecode.c. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: python-pillow as
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2021-01-18·CVSS 7.1
CVE-2020-35655 [HIGH] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Pillow could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that Pillow incorrectly handled certain PCX image files.
If a user or automated system were tricked into opening a specially-crafted
PCX file, a remote attacker could possibly cause Pillow to crash,
resulting in a denial of service. (CVE-2020-35653)
It was discovered that Pillow incorrectly handled certain Tiff image files.
If a user or automated system were tricked into opening a specially-crafted
Tiff file, a remote attacker could cause Pillow to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2020-35654)
It was discovered that Pillow inc
Red Hat
python-pillow: decoding crafted YCbCr files could result in heap-based buffer overflow
vendor_redhat·2021-01-03·CVSS 8.8
CVE-2020-35654 [HIGH] CWE-787 python-pillow: decoding crafted YCbCr files could result in heap-based buffer overflow
python-pillow: decoding crafted YCbCr files could result in heap-based buffer overflow
In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.
A flaw was found in python-pillow. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: python-pillow as shipped with Red Hat Enterprise Linux 7 and 8 are not affected by this flaw as the flaw was introduced in a newer version than shipped.
Package: python-pillow (Red Hat Enterprise Linux 7) - Not affected
Pack
Debian
CVE-2021-25289: pillow - An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buff...
vendor_debian·2021·CVSS 8.8
CVE-2021-25289 [HIGH] CVE-2021-25289: pillow - An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buff...
An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for CVE-2020-35654.
Scope: local
bookworm: resolved (fixed in 8.1.1-1)
bullseye: resolved (fixed in 8.1.1-1)
forky: resolved (fixed in 8.1.1-1)
sid: resolved (fixed in 8.1.1-1)
trixie: resolved (fixed in 8.1.1-1)
Debian
CVE-2020-35654: pillow - In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decodin...
vendor_debian·2020·CVSS 8.8
CVE-2020-35654 [HIGH] CVE-2020-35654: pillow - In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decodin...
In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.
Scope: local
bookworm: resolved (fixed in 8.1.0-1)
bullseye: resolved (fixed in 8.1.0-1)
forky: resolved (fixed in 8.1.0-1)
sid: resolved (fixed in 8.1.0-1)
trixie: resolved (fixed in 8.1.0-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6BYVI5G44MRIPERKYDQEL3S3YQCZTVHE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BF553AMNNNBW7SH4IM4MNE4M6GNZQ7YD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQQY6472RX4J2SUJENWDZAWKTJJGP2ML/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZTSY25UJU7NJUFHH3HWT575LT4TDFWBZ/https://pillow.readthedocs.io/en/stable/releasenotes/index.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6BYVI5G44MRIPERKYDQEL3S3YQCZTVHE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BF553AMNNNBW7SH4IM4MNE4M6GNZQ7YD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQQY6472RX4J2SUJENWDZAWKTJJGP2ML/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZTSY25UJU7NJUFHH3HWT575LT4TDFWBZ/https://pillow.readthedocs.io/en/stable/releasenotes/index.html
2021-01-12
Published