libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*",
"extracted_events": [
{
"last_affected": "14.04"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*",
"extracted_events": [
{
"last_affected": "16.04"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"extracted_events": [
{
"last_affected": "18.04"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "19.10"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "30"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "31"
}
],
"source": "CPE_FIELD"
}
]
}{
"cpe": "cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "6.2.2"
}
],
"source": [
"CPE_FIELD",
"REFERENCES"
]
}[
{
"target": {
"file": "src/libImaging/TiffDecode.c"
},
"id": "CVE-2020-5310-dd6ea137",
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/python-pillow/pillow/commit/4e2def2539ec13e53a82e06c4b3daf00454100c4",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"11063566985366830361541805365964257484",
"10227853089858799829606132986670377937",
"317038433496737873798409669386881171228",
"117583418836728761439750076620579841509",
"42548093785476519379886330909429997892",
"180296352043842206907328859036068743446",
"232392863528886449003010581525191622890",
"170708454611785382970649880980374429778",
"194205829702377816602101179673064497694",
"233404740975746542367800271115279682632",
"263102630687762320497076038078445684335",
"195294903843144035227280250434198303035",
"31124841263578157110148021800467585987",
"310907908465319355122623942791978593816",
"339390408024927267804818065141722014459"
]
}
},
{
"target": {
"function": "ImagingLibTiffDecode",
"file": "src/libImaging/TiffDecode.c"
},
"id": "CVE-2020-5310-ebcc8c54",
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/python-pillow/pillow/commit/4e2def2539ec13e53a82e06c4b3daf00454100c4",
"signature_type": "Function",
"digest": {
"function_hash": "56824892614320334599794661287660083213",
"length": 4897.0
}
}
]
"2026-04-12T00:01:42Z"
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-5310.json"