CVE-2020-5312: Buffer Overflow
A flaw was discovered in python-pillow does where it does not properly restrict operations within the bounds of a memory buffer when decoding PCX images. An application that uses python-pillow to decode untrusted images may be vulnerable to this flaw, which can allow an attacker to crash the application or potentially execute code on the system.
Other sources
libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
libImaging/PcxDecode.c in Pillow before 6.2.2 has an PCX P mode buffer overflow.
Upstream patch:
https://github.com/python-pillow/Pillow/commit/93b22b846e0269ee9594ff71a72bec02d2bea8fd
References:
https://pillow.readthedocs.io/en/stable/releasenotes/6.2.2.html
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/python-imagingto a version that resolves this vulnerability.Fixed in 0:1.1.6-20.el6_10 - Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 0:2.0.0-20.gitd1c6db8.el7_7 - Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 0:5.1.1-10.el8_1 - Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 0:5.1.1-10.el8_0 - Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 6.2.2 - Upgrade
Upgrade
pip/Pillowto a version that resolves this vulnerability.Fixed in 6.2.2 - Upgrade
Upgrade
debian/pillowto a version that resolves this vulnerability.Fixed in 8.1.2+dfsg-0.3+deb11u2Fixed in 8.1.2+dfsg-0.3+deb11u3Fixed in 9.4.0-1.1+deb12u1Fixed in 11.1.0-5+deb13u4Fixed in 11.1.0-5+deb13u3Fixed in 12.2.0-1Fixed in 12.3.0-1 - Upgrade
Upgrade
python-pillow/Pillowto a version that resolves this vulnerability.Fixed in 6.2.2Patch 93b22b846e0269ee9594ff71a72bec02d2bea8fd
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-5312?
CVE-2020-5312 is a vulnerability in libImaging/PcxDecode.c in Pillow before 6.2.2 that allows a PCX P mode buffer overflow.
What is the severity of CVE-2020-5312?
The severity of CVE-2020-5312 is critical with a severity score of 9.8.
How does CVE-2020-5312 affect python-pillow?
CVE-2020-5312 affects python-pillow versions before 6.2.2.
How can I fix the vulnerability CVE-2020-5312?
To fix the vulnerability CVE-2020-5312, update python-pillow to version 6.2.2 or later.
Where can I find more information about CVE-2020-5312?
You can find more information about CVE-2020-5312 in the references provided: [link1](https://github.com/python-pillow/Pillow/commit/93b22b846e0269ee9594ff71a72bec02d2bea8fd), [link2](https://pillow.readthedocs.io/en/stable/releasenotes/6.2.2.html), [link3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1789541).