Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-35655

Опубликовано: 03 янв. 2021
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.

A flaw was found in python-pillow. SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7python-pillowOut of support scope
Red Hat Enterprise Linux 9python-pillowNot affected
Red Hat Quay 3quay/quay-builder-qemu-rhcos-rhel8Not affected
Red Hat Quay 3quay/quay-rhel8Affected
Red Hat Enterprise Linux 8python-pillowFixedRHSA-2021:414909.11.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1915432python-pillow: Buffer over-read in SGI RLE image reader

EPSS

Процентиль: 50%
0.00269
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 5 лет назад

In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.

CVSS3: 5.4
nvd
около 5 лет назад

In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.

CVSS3: 5.4
debian
около 5 лет назад

In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read whe ...

CVSS3: 5.4
github
почти 5 лет назад

Pillow Out-of-bounds Read

suse-cvrf
больше 4 лет назад

Security update for python-CairoSVG, python-Pillow

EPSS

Процентиль: 50%
0.00269
Низкий

5.4 Medium

CVSS3