CVE-2020-10379

HIGH

Python Pillow < 7.1.0 - Buffer Overflow

Title source: rule
STIX 2.1

Description

In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.

Scores

CVSS v3 7.8
EPSS 0.0036
EPSS Percentile 58.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (5)
canonical/ubuntu_linux 20.04
fedoraproject/fedora 31
fedoraproject/fedora 32
pypi/pillow 0 - 7.1.0PyPI
python/pillow < 7.1.0
Published Jun 25, 2020
Tracked Since Feb 18, 2026