QID 982911
QID 982911: Python (pip) Security Update for Pillow (GHSA-hf64-x4gq-p99h)
In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hf64-x4gq-p99h for updates pertaining to this vulnerability.
Vendor References
- GHSA-hf64-x4gq-p99h -
github.com/advisories/GHSA-hf64-x4gq-p99h
CVEs related to QID 982911
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hf64-x4gq-p99h | Pillow |
|