First published: Thu Jun 25 2020(Updated: )
In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/python-pillow | <0:5.1.1-12.el8_2 | 0:5.1.1-12.el8_2 |
redhat/python-pillow | <0:5.1.1-11.el8_0 | 0:5.1.1-11.el8_0 |
redhat/python-pillow | <0:5.1.1-11.el8_1 | 0:5.1.1-11.el8_1 |
Python Pillow | <=7.0.0 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =20.04 | |
redhat/python-pillow | <7.1.0 | 7.1.0 |
ubuntu/pillow | <5.1.0-1ubuntu0.3 | 5.1.0-1ubuntu0.3 |
ubuntu/pillow | <7.0.0-4ubuntu0.1 | 7.0.0-4ubuntu0.1 |
ubuntu/pillow | <7.1.0 | 7.1.0 |
debian/pillow | 5.4.1-2+deb10u3 5.4.1-2+deb10u6 8.1.2+dfsg-0.3+deb11u1 9.4.0-1.1 10.3.0-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-11538 is a vulnerability found in python-pillow, which allows an attacker to crash the application or execute code on the system.
CVE-2020-11538 has a severity rating of 8.1, which is considered high.
CVE-2020-11538 affects python-pillow by introducing an out-of-bounds read/write flaw during decoding of SGI RLE images.
To fix CVE-2020-11538, update python-pillow to version 7.1.0 or later.
You can find more information about CVE-2020-11538 on the MITRE CVE website, the GitHub page for python-pillow, and the release notes for python-pillow version 7.1.0.