RHSA-2020:3887: Moderate: python-pillow security update
The python-pillow packages contain a Python image processing library that provides extensive file format support, an efficient internal representation, and powerful image-processing capabilities.<br>Security Fix(es):<br><li> python-pillow: out-of-bounds read in ImagingFliDecode when loading FLI images (CVE-2020-5313)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.9 Release Notes linked from the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3887?
The severity of RHSA-2020:3887 is considered moderate due to an out-of-bounds read in the python-pillow package.
How do I fix RHSA-2020:3887?
To fix RHSA-2020:3887, update the python-pillow package to version 2.0.0-21.gitd1c6db8.el7 or later.
Which versions of python-pillow are affected by RHSA-2020:3887?
Versions of python-pillow prior to 2.0.0-21.gitd1c6db8.el7 are affected by RHSA-2020:3887.
What type of issue is reported in RHSA-2020:3887?
RHSA-2020:3887 reports an out-of-bounds read vulnerability in the python-pillow package.
Do any other packages depend on python-pillow affected by RHSA-2020:3887?
Yes, multiple packages including python-pillow-devel and python-pillow-doc may rely on the affected python-pillow package.