VDB

ALINUX2-SA-2020%3A0024

ALINUX2-SA-2020%3A0024 PUBLISHED CVSS 7.5 HIGH

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2019-16865: An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image. CVE-2020-5312: libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Alibaba Cloudpython-pillow

Timeline

  • Feb 28, 2020 CVE Published
  • Feb 28, 2020 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›