CVE-2020-35653: Input Validation
A flaw was found in python-pillow. The PcxDecode in Pillow has a buffer over-read when decoding a crafted PCX file due to the user-supplied stride value trusted for buffer calculations. The highest threat from this vulnerability is to system availability.
Other sources
In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this flaw in python-pillow?
The vulnerability ID of this flaw in python-pillow is CVE-2020-35653.
What is the severity level of CVE-2020-35653?
CVE-2020-35653 has a severity level of high.
How does CVE-2020-35653 impact system availability?
The highest threat from CVE-2020-35653 is to system availability.
Which versions of python-pillow are affected by CVE-2020-35653?
Versions up to and excluding 8.1.0 of python-pillow are affected by CVE-2020-35653.
How can I fix CVE-2020-35653?
To fix CVE-2020-35653, you need to update python-pillow to version 8.1.0 or later.