CVE-2020-10177

Out-of-bounds Read in pypi/Pillow

Identifiers

CVE-2020-10177

Package Slug

pypi/Pillow

Vulnerability

Out-of-bounds Read

Description

Pillow has multiple out-of-bounds reads in libImaging/FliDecode.c.

Affected Versions

All versions before 6.2.3, version 7.0.0

Solution

Upgrade to version 7.1.0 or above.

Last Modified

2020-07-03

source