VDB

PYSEC-2021-71

PYSEC-2021-71 PUBLISHED

In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.

Affected Products

VendorProductVersions
PyPIpillow4.3.0, 4.3.0, 5.1.0

Timeline

  • Jan 12, 2021 CVE Published
  • Dec 6, 2023 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›