VDB
ALINUX2-SA-2020%3A0024
ALINUX2-SA-2020%3A0024
PUBLISHED
CVSS 7.5 HIGH
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2019-16865: An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image. CVE-2020-5312: libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | python-pillow |
Timeline
- Feb 28, 2020 CVE Published
- Feb 28, 2020 CVE Updated