Buffer Over-read Vulnerability in Pillow Image Processing Library
CVE-2020-35655
5.4MEDIUM
Summary
Pillow, a widely used image processing library in Python, is affected by a buffer over-read vulnerability in the SGIRleDecode function. This issue arises when the library is tasked with decoding specially crafted SGI RLE image files, leading to mishandled offsets and length tables. As a result, the library may read beyond allocated memory boundaries, potentially exposing sensitive information or causing application crashes.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved