CVE-2020-10379: Buffer Overflow
In Pillow before 6.2.3 and 7.x before 7.0.1, there are two Buffer Overflows in libImaging/TiffDecode.c.
Pull Request:
https://github.com/python-pillow/Pillow/pull/4538
Upstream Advisory:
https://pillow.readthedocs.io/en/stable/releasenotes/7.1.0.html
Upstream Advisory:
https://pillow.readthedocs.io/en/stable/releasenotes/6.2.3.html
Other sources
In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.
— GitHub
In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-10379?
CVE-2020-10379 is a vulnerability in Pillow before version 7.1.0, where there are two Buffer Overflows in libImaging/TiffDecode.c.
How severe is CVE-2020-10379?
CVE-2020-10379 has a severity value of 7.8, which is considered high.
What software are affected by CVE-2020-10379?
Pillow versions up to 7.1.0, python-pillow versions up to 7.1.0, and Ubuntu's pillow versions up to 7.0.0-4ubuntu0.1 and 7.1.0 are affected by CVE-2020-10379.
How do I fix CVE-2020-10379?
To fix CVE-2020-10379, you need to update your Pillow software to version 7.1.0.
Where can I find more information about CVE-2020-10379?
You can find more information about CVE-2020-10379 in the National Vulnerability Database (NVD) at https://nvd.nist.gov/vuln/detail/CVE-2020-10379.