Skip to content

Conversation

@radarhere
Copy link
Member

CVE-2020-35655, 4 Byte Read Overflow in SGIRleDecode.c, where the code was not correctly checking the offsets and length tables. Independently reported through Tidelift and Google's OSS-Fuzz. This vulnerability covers Pillow versions 4.3.0->8.0.1.

wiredfool and others added 3 commits January 2, 2021 20:09
* Independently found by a contributor and sent to Tidelift, and by Google's OSS Fuzz.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants