Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-11538

Опубликовано: 01 июл. 2020
Источник: redhat
CVSS3: 8.1

Описание

In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.

An out-of-bounds read/write flaw was found in python-pillow, in the way SGI RLE images are decoded. An application that uses python-pillow to decode untrusted images may be vulnerable. This flaw allows an attacker to crash the application or potentially execute code on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

This issue did not affect the versions of python-pillow and python-imaging as shipped with Red Hat Enterprise Linux 5, 6, and 7 as they did not include the SGI RLE image decoder, where the flaw lies.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5python-imagingNot affected
Red Hat Enterprise Linux 6python-imagingNot affected
Red Hat Enterprise Linux 7python-pillowNot affected
Red Hat Enterprise Linux 8python-pillowFixedRHSA-2020:318528.07.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutionspython-pillowFixedRHSA-2020:330204.08.2020
Red Hat Enterprise Linux 8.1 Extended Update Supportpython-pillowFixedRHSA-2020:329904.08.2020
Red Hat Quay 3quay/clair-rhel8FixedRHSA-2021:042004.02.2021
Red Hat Quay 3quay/quay-bridge-operator-bundleFixedRHSA-2021:042004.02.2021
Red Hat Quay 3quay/quay-bridge-operator-rhel8FixedRHSA-2021:042004.02.2021
Red Hat Quay 3quay/quay-builder-qemu-rhcos-rhel8FixedRHSA-2021:042004.02.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1852814python-pillow: out-of-bounds reads/writes in the parsing of SGI image files in expandrow/expandrow2

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 5 лет назад

In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.

CVSS3: 8.1
nvd
больше 5 лет назад

In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.

CVSS3: 8.1
debian
больше 5 лет назад

In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out- ...

CVSS3: 8.1
github
больше 5 лет назад

Out-of-bounds read in Pillow

rocky
больше 5 лет назад

Important: python-pillow security update

8.1 High

CVSS3