HIGH 8.1 PyPI

Out-of-bounds read in Pillow

GHSA-43fq-w8qq-v88h · BIT-pillow-2020-11538 · CVE-2020-11538 · PYSEC-2020-80

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.

Ready to move

Start Securing

Free, no credit card | First findings in minutes