CVE-2020-5311
CRITICAL9.8EPSS 1.1%Buffer Copy without Checking Size of Input in Pillow
發布日:2022/5/24修改日:2026/4/28
描述
libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
受影響套件(5)
- Alpine/py3-pillowfrom 0, < 6.2.2-r0
- Bitnami/pillowfrom 0, < 6.2.2
- Debian/pillowfrom 0, < 7.0.0-1
- PyPI/pillowfrom 0, < 6.2.2
- PyPI/pillowfrom 0, < a79b65c47c7dc6fe623aadf09aa6192fc54548f3 | from 0, < 6.2.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
參考連結(19)
- ADVISORYhttps://github.com/advisories/GHSA-r7rm-8j6h-r933
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2020-5311
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2020-5311
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2020-5311
- PATCHhttps://github.com/python-pillow/Pillow
- WEBhttps://access.redhat.com/errata/RHSA-2020:0566
- WEBhttps://access.redhat.com/errata/RHSA-2020:0580
- WEBhttps://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2020-82.yaml
- WEBhttps://github.com/python-pillow/Pillow/commit/a79b65c47c7dc6fe623aadf09aa6192fc54548f3
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MMU3WT2X64GS5WHDPKKC2WZA7UIIQ3A/
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3DUMIBUYGJRAVJCTFUWBRLVQKOUTVX5P/
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/2MMU3WT2X64GS5WHDPKKC2WZA7UIIQ3A
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/2MMU3WT2X64GS5WHDPKKC2WZA7UIIQ3A/
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/3DUMIBUYGJRAVJCTFUWBRLVQKOUTVX5P
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/3DUMIBUYGJRAVJCTFUWBRLVQKOUTVX5P/
- WEBhttps://pillow.readthedocs.io/en/stable/releasenotes/6.2.2.html
- WEBhttps://usn.ubuntu.com/4272-1
- WEBhttps://usn.ubuntu.com/4272-1/
- WEBhttps://www.debian.org/security/2020/dsa-4631