CVE-2020-10177: Medium severity Python Pillow vulnerability
A flaw was found in python-pillow. Multiple out-of-bounds reads occur in libImaging/FliDecode.c.
Other sources
Pillow before 6.2.3 and 7.x before 7.0.1 has multiple out-of-bounds reads in libImaging/FliDecode.c.
Pull Request:
https://github.com/python-pillow/Pillow/pull/4538
Upstream Advisory:
https://pillow.readthedocs.io/en/stable/releasenotes/7.1.0.html
Upstream Advisory:
https://pillow.readthedocs.io/en/stable/releasenotes/6.2.3.html
— Red Hat
Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.
— GitHub
Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10177?
The severity of CVE-2020-10177 is medium with a severity value of 5.9.
What is the affected software for CVE-2020-10177?
The affected software for CVE-2020-10177 includes python-pillow versions up to and excluding 7.1.0, pillow versions up to and excluding 3.1.2-0ubuntu1.4, 5.1.0-1ubuntu0.3, and 7.1.0, and debian/pillow versions up to and excluding 5.4.1-2+deb10u3, 8.1.2+dfsg-0.3+deb11u1, 9.4.0-1.1, and 10.0.0-1.
How do I fix CVE-2020-10177 in python-pillow?
To fix CVE-2020-10177 in python-pillow, update to version 7.1.0 or later.
How do I fix CVE-2020-10177 in pillow for Ubuntu?
To fix CVE-2020-10177 in pillow for Ubuntu, update to version 3.1.2-0ubuntu1.4, 5.1.0-1ubuntu0.3, or 7.1.0 depending on the Ubuntu release.
How do I fix CVE-2020-10177 in debian/pillow?
To fix CVE-2020-10177 in debian/pillow, update to version 5.4.1-2+deb10u3, 8.1.2+dfsg-0.3+deb11u1, 9.4.0-1.1, or 10.0.0-1.