CVE-2020-5313: Buffer Overflow
libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
Other sources
An out-of-bounds read was discovered in python-pillow in the way it decodes FLI images. An application that uses python-pillow to load untrusted images may be vulnerable to this flaw, which can allow an attacker to read the memory of the application they should be not allowed to read.
libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 0:2.0.0-21.gitd1c6db8.el7 - Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 0:5.1.1-12.el8_2 - Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 6.2.2 - Upgrade
Upgrade
pip/Pillowto a version that resolves this vulnerability.Fixed in 6.2.2 - Upgrade
Upgrade
debian/pillowto a version that resolves this vulnerability.Fixed in 8.1.2+dfsg-0.3+deb11u2Fixed in 8.1.2+dfsg-0.3+deb11u3Fixed in 9.4.0-1.1+deb12u1Fixed in 11.1.0-5+deb13u4Fixed in 11.1.0-5+deb13u3Fixed in 12.2.0-1Fixed in 12.3.0-1 - Upgrade
Upgrade
python-pillow/Pillowto a version that resolves this vulnerability.Fixed in 6.2.2Patch a09acd0decd8a87ccce939d5ff65dab59e7d365b
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this flaw?
The vulnerability ID is CVE-2020-5313.
What is the severity of CVE-2020-5313?
The severity of CVE-2020-5313 is high, with a severity value of 8.2.
What is the affected software?
The affected software is python-pillow.
Which version(s) of python-pillow are affected?
python-pillow versions before 6.2.2 are affected.
How can the vulnerability be fixed?
The vulnerability can be fixed by updating python-pillow to version 6.2.2 or later.