QID 982881

QID 982881: Python (pip) Security Update for Pillow (GHSA-57h3-9rgr-c24m)

An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for CVE-2020-35654.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-57h3-9rgr-c24m for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982881

    Software Advisories
    Advisory ID Software Component Link
    GHSA-57h3-9rgr-c24m Pillow URL Logo github.com/advisories/GHSA-57h3-9rgr-c24m