5.8
CVSSv2

CVE-2020-5313

Published: 03/01/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.1 | Impact Score: 4.2 | Exploitability Score: 2.8
VMScore: 517
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

libImaging/FliDecode.c in Pillow prior to 6.2.2 has an FLI buffer overflow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

python pillow

debian debian linux 9.0

debian debian linux 10.0

canonical ubuntu linux 18.04

fedoraproject fedora 30

canonical ubuntu linux 14.04

canonical ubuntu linux 19.10

fedoraproject fedora 31

canonical ubuntu linux 16.04

Vendor Advisories

Debian Bug report logs - #948224 pillow: CVE-2019-19911 CVE-2020-5310 CVE-2020-5311 CVE-2020-5312 CVE-2020-5313 Package: pillow; Maintainer for pillow is Matthias Klose <doko@debianorg>; Reported by: Markus Koschany <apo@debianorg> Date: Sun, 5 Jan 2020 15:33:01 UTC Severity: grave Tags: security Found in version ...
Several security issues were fixed in Pillow ...
Multiple security issues were discovered in Pillow, a Python imaging library, which could result in denial of service and potentially the execution of arbitrary code if malformed PCX, FLI, SGI or TIFF images are processed For the oldstable distribution (stretch), these problems have been fixed in version 400-4+deb9u1 For the stable distribution ...
Synopsis Moderate: Red Hat Quay v340 security update Type/Severity Security Advisory: Moderate Topic Red Hat Quay 340 is now available with bug fixes and variousenhancementsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVS ...
Synopsis Moderate: python-pillow security update Type/Severity Security Advisory: Moderate Topic An update for python-pillow is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) ba ...
Synopsis Important: python-pillow security update Type/Severity Security Advisory: Important Topic An update for python-pillow is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) ...
Synopsis Moderate: security update - Red Hat Ansible Tower 36 runner release (CVE-2019-18874) Type/Severity Security Advisory: Moderate Topic Red Hat Ansible Tower 36 runner release (CVE-2019-18874) Description Updated python-psutil version to 566 inside ansible-runner container(CVE-20 ...
Synopsis Moderate: security update - Red Hat Ansible Tower 37 runner release (CVE-2019-18874) Type/Severity Security Advisory: Moderate Topic Red Hat Ansible Tower 37 runner release (CVE-2019-18874) Description Updated python-psutil version to 566 inside ansible-runner container (CVE-2 ...
An out-of-bounds read was discovered in python-pillow in the way it decodes FLI images An application that uses python-pillow to load untrusted images may be vulnerable to this flaw, which can allow an attacker to read the memory of the application they should be not allowed to read (CVE-2020-5313) ...

Github Repositories

天天生鲜-django22版本 简介 本项目替换原项目框架django18为最新版的django225(已修复为2210),该项目包含了实际开发中的电商项目中大部分的功能开发和知识点实践, 是一个非常不错的django学习项目,同时也记录在替换框架中遇到的坑,所遇到的django1x和2x的区别,希望对各位的学

天天生鲜-django22版本 帮人做的毕业设计 fork 自 githubcom/Pad0y/Django2_dailyfresh 大部分提交在码云上完成,因为网络问题没同步更新到github 修改如下: 修改了大部分代码包的导入方式(原来clone下来在Pycharm下直接一大片飘红),并运行服务, 调通了支付宝支付接口, 删除了可能