Safety vulnerability ID: 38451
The information on this page was manually curated by our Cybersecurity Intelligence Team.
In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.
Latest version: 11.0.0
Python Imaging Library (Fork)
In libImaging/Jpeg2KDecode.c in Pillow before 7.0.0, there are multiple out-of-bounds reads via a crafted JP2 file.
MISC:https://github.com/python-pillow/Pillow/commits/master/src/libImaging/: https://github.com/python-pillow/Pillow/commits/master/src/libImaging/
MISC:https://github.com/python-pillow/Pillow/pull/4505: https://github.com/python-pillow/Pillow/pull/4505
MISC:https://github.com/python-pillow/Pillow/pull/4538: https://github.com/python-pillow/Pillow/pull/4538
MISC:https://pillow.readthedocs.io/en/stable/releasenotes/: https://pillow.readthedocs.io/en/stable/releasenotes/
MISC:https://pillow.readthedocs.io/en/stable/releasenotes/7.1.0.html: https://pillow.readthedocs.io/en/stable/releasenotes/7.1.0.html
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application