QID 980743
QID 980743: Python (pip) Security Update for Pillow (GHSA-43fq-w8qq-v88h)
In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-43fq-w8qq-v88h for updates pertaining to this vulnerability.
Vendor References
- GHSA-43fq-w8qq-v88h -
github.com/advisories/GHSA-43fq-w8qq-v88h
CVEs related to QID 980743
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-43fq-w8qq-v88h | Pillow |
|