QID 980999
QID 980999: Python (pip) Security Update for Pillow (GHSA-7r7m-5h27-29hp)
An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-7r7m-5h27-29hp for updates pertaining to this vulnerability.
Vendor References
- GHSA-7r7m-5h27-29hp -
github.com/advisories/GHSA-7r7m-5h27-29hp
CVEs related to QID 980999
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7r7m-5h27-29hp | Pillow |
|