Description
In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0181 | In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. |
Github GHSA |
GHSA-vqcj-wrf2-7v73 | Pillow Out-of-bounds Write |
Ubuntu USN |
USN-4697-1 | Pillow vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T17:09:14.408Z
Reserved: 2020-12-23T00:00:00.000Z
Link: CVE-2020-35654
No data.
Status : Modified
Published: 2021-01-12T09:15:13.917
Modified: 2024-11-21T05:27:46.270
Link: CVE-2020-35654
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN