PublicDateAtUSN: 2020-01-03 01:15:00 UTC Candidate: CVE-2020-5310 PublicDate: 2020-01-03 01:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-5310 https://pillow.readthedocs.io/en/stable/releasenotes/6.2.2.html https://ubuntu.com/security/notices/USN-4272-1 Description: libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=948224 Priority: medium Discovered-by: Assigned-to: leosilva CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_pillow: upstream: https://github.com/python-pillow/Pillow/commit/4e2def2539ec13e53a82e06c4b3daf00454100c4 upstream_pillow: released (7.0.0-1) precise/esm_pillow: DNE trusty_pillow: ignored (out of standard support) trusty/esm_pillow: not-affected xenial_pillow: not-affected esm-infra/xenial_pillow: not-affected bionic_pillow: not-affected disco_pillow: ignored (reached end-of-life) eoan_pillow: released (6.1.0-1ubuntu0.2) devel_pillow: released (7.0.0-4)