CVE-2020-5310: Integer Overflow
libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.
Other sources
libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 6.2.2 - Upgrade
Upgrade
pip/pillowto a version that resolves this vulnerability.Fixed in 6.2.2 - Upgrade
Upgrade
debian/pillowto a version that resolves this vulnerability.Fixed in 8.1.2+dfsg-0.3+deb11u2Fixed in 8.1.2+dfsg-0.3+deb11u3Fixed in 9.4.0-1.1+deb12u1Fixed in 11.1.0-5+deb13u4Fixed in 11.1.0-5+deb13u3Fixed in 12.2.0-1Fixed in 12.3.0-1 - Upgrade
Upgrade
Pillowto a version that resolves this vulnerability.Fixed in 6.2.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 4e2def2539ec13e53a82e06c4b3daf00454100c4
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-5310.
What is the severity of CVE-2020-5310?
The severity of CVE-2020-5310 is high with a severity score of 8.1.
What is the affected software?
The affected software is Pillow versions before 6.2.2.
How can I fix the vulnerability?
To fix the vulnerability, upgrade to Pillow version 6.2.2 or later.
Where can I find more information about CVE-2020-5310?
You can find more information about CVE-2020-5310 at the following references: [GitHub Commit](https://github.com/python-pillow/Pillow/commit/4e2def2539ec13e53a82e06c4b3daf00454100c4), [Release Notes](https://pillow.readthedocs.io/en/stable/releasenotes/6.2.2.html), and [Bugzilla Report](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1789541).