CVE-2020-35655 PUBLISHED

In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.

EPSS 0.27% · 50.2th percentile

Risk Scores

EPSS Score
0.27%
50.2th percentile

Affected Products

VendorProductVersions
Bitnamipillow4.3.0
Bitnamipillow4.3.0

Timeline

References

Open in Interactive Console →