Out-of-bounds Read The advisory has been revoked - it doesn't affect any version of package pillow  (opens in a new tab)


Threat Intelligence

Exploit Maturity
Proof of Concept

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-PILLOW-1727377
  • published1 Oct 2021
  • disclosed1 Oct 2021
  • creditUnknown

Introduced: 1 Oct 2021

CVE NOT AVAILABLE CWE-125  (opens in a new tab)

Amendment

This was deemed not a vulnerability.

Overview

Affected versions of this package are vulnerable to Out-of-bounds Read. The previous bounds check in FilDecode.c incorrectly calculated the required read buffer size when copying a chunk, potentially reading six extra bytes off the end of the allocated buffer from the heap.

References