QID 980520
QID 980520: Python (pip) Security Update for pillow (GHSA-7534-mm45-c74v)
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-7534-mm45-c74v for updates pertaining to this vulnerability.
Vendor References
- GHSA-7534-mm45-c74v -
github.com/advisories/GHSA-7534-mm45-c74v
CVEs related to QID 980520
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7534-mm45-c74v | pillow |
|