HIGH
python-pillow: Buffer over-read in PCX image reader
Published Jan 12, 2021
8.3
HIGHCVSS 4.0
EPSS 1.64%
Description
In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations.
Affected products
No data.
Configuration 2
OR
- 32
- 33
Configuration 3
- 9.0
No data.
Red Hat Enterprise Linux 8
python-pillow-0:5.1.1-16.el8
Fixed · RHSA-2021:4149
Red Hat Quay 3
quay/quay-rhel8:v3.6.0-62
Fixed · RHSA-2021:3917
Red Hat Enterprise Linux 7
python-pillow
Out of support scope
Red Hat Enterprise Linux 9
python-pillow
Not affected
Red Hat Quay 3
quay/quay-builder-qemu-rhcos-rhel8
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | python-pillow-0:5.1.1-16.el8 | Fixed | RHSA-2021:4149 |
| Red Hat Quay 3 | quay/quay-rhel8:v3.6.0-62 | Fixed | RHSA-2021:3917 |
| Red Hat Enterprise Linux 7 | python-pillow | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | python-pillow | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-builder-qemu-rhcos-rhel8 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (15)
- https://access.redhat.com/security/cve/CVE-2020-35653 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1915420 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-0180 Advisory
- https://github.com/advisories/GHSA-f5g8-5qq7-938w Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2021-69.yaml
- https://github.com/python-pillow/Pillow/commit/2f409261eb1228e166868f8f0b5da5cda52e55bf
- https://lists.debian.org/debian-lts-announce/2021/07/msg00018.html mailing-listx_refsource_MLISTMailing List
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6BYVI5G44MRIPERKYDQEL3S3YQCZTVHE/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BF553AMNNNBW7SH4IM4MNE4M6GNZQ7YD/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6BYVI5G44MRIPERKYDQEL3S3YQCZTVHE
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BF553AMNNNBW7SH4IM4MNE4M6GNZQ7YD
- https://nvd.nist.gov/vuln/detail/CVE-2020-35653
- https://pillow.readthedocs.io/en/stable/releasenotes/8.1.0.html#security
- https://pillow.readthedocs.io/en/stable/releasenotes/index.html x_refsource_MISCRelease NotesThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-35653
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 12, 2021
Updated Aug 4, 2024
Reserved Dec 23, 2020
Link CVE-2020-35653
CISA Vulnrichment
No data
GitHub
Link GHSA-F5G8-5QQ7-938W