CVE-2020-35655: Medium severity python imaging library (pillow) vulnerability
A flaw was found in python-pillow. SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.
Other sources
In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-35655?
The severity of CVE-2020-35655 is medium with a CVSS score of 5.4.
How does CVE-2020-35655 impact systems?
CVE-2020-35655 can lead to a 4-byte buffer over-read when decoding crafted SGI RLE image files in python-pillow.
Which versions of python-pillow are affected by CVE-2020-35655?
CVE-2020-35655 affects python-pillow versions up to but excluding 8.1.0.
How can I fix CVE-2020-35655?
To fix CVE-2020-35655, update python-pillow to version 8.1.0 or later.
Where can I find more information about CVE-2020-35655?
You can find more information about CVE-2020-35655 on the CVE website, NIST NVD, and the official Pillow release notes.