libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.
References
Link | Resource |
---|---|
https://pillow.readthedocs.io/en/stable/releasenotes/9.1.1.html | Release Notes Third Party Advisory |
https://github.com/python-pillow/Pillow/blob/main/src/libImaging/TgaRleDecode.c | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-05-25 05:15
Updated : 2022-06-03 07:25
NVD link : CVE-2022-30595
Mitre link : CVE-2022-30595
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
python
- pillow