QID 980742
QID 980742: Python (pip) Security Update for Pillow (GHSA-vj42-xq3r-hr3r)
In libImaging/Jpeg2KDecode.c in Pillow before 7.0.0, there are multiple out-of-bounds reads via a crafted JP2 file.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vj42-xq3r-hr3r for updates pertaining to this vulnerability.
Vendor References
- GHSA-vj42-xq3r-hr3r -
github.com/advisories/GHSA-vj42-xq3r-hr3r
CVEs related to QID 980742
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vj42-xq3r-hr3r | Pillow |
|