CVE-2020-5311: Buffer Overflow
libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
Other sources
An out-of-bounds write flaw was discovered in python-pillow in the way SGI RLE images are decoded. An application that uses python-pillow to decode untrusted images may be vulnerable to this flaw, which can allow an attacker to crash the application or potentially execute code on the system.
libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 0:5.1.1-10.el8_1 - Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 0:5.1.1-10.el8_0 - Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 6.2.2 - Upgrade
Upgrade
pip/pillowto a version that resolves this vulnerability.Fixed in 6.2.2 - Upgrade
Upgrade
debian/pillowto a version that resolves this vulnerability.Fixed in 8.1.2+dfsg-0.3+deb11u2Fixed in 8.1.2+dfsg-0.3+deb11u3Fixed in 9.4.0-1.1+deb12u1Fixed in 11.1.0-5+deb13u4Fixed in 11.1.0-5+deb13u3Fixed in 12.2.0-1Fixed in 12.3.0-1 - Upgrade
Upgrade
python-pillow/Pillowto a version that resolves this vulnerability.Fixed in 6.2.2
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-5311?
CVE-2020-5311 is a vulnerability in the libImaging/SgiRleDecode.c file in Pillow before version 6.2.2.
How does CVE-2020-5311 affect Python Pillow?
CVE-2020-5311 allows an attacker to crash an application or potentially execute code on the system by exploiting an out-of-bounds write flaw in the SGI RLE image decoding process of python-pillow.
What is the severity of CVE-2020-5311?
CVE-2020-5311 has a severity rating of critical, with a severity value of 9 out of 10.
How can I fix CVE-2020-5311?
To fix CVE-2020-5311, ensure you are using python-pillow version 6.2.2 or later.
Where can I find more information about CVE-2020-5311?
You can find more information about CVE-2020-5311 in the references provided: [GitHub commit](https://github.com/python-pillow/Pillow/commit/a79b65c47c7dc6fe623aadf09aa6192fc54548f3), [Pillow release notes](https://pillow.readthedocs.io/en/stable/releasenotes/6.2.2.html), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1789541).