5.8
CVSSv2

CVE-2020-35653

Published: 12/01/2021 Updated: 14/01/2021
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.1 | Impact Score: 4.2 | Exploitability Score: 2.8
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

In Pillow prior to 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

python pillow