CVE-2020-5310

Source
https://cve.org/CVERecord?id=CVE-2020-5310
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-5310.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-5310
Aliases
Downstream
Published
2020-01-03T01:15:11.087Z
Modified
2026-04-16T00:09:31.772330443Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.

Database specific
{
    "unresolved_ranges": [
        {
            "cpe": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "14.04"
                }
            ],
            "source": "CPE_FIELD"
        },
        {
            "cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "16.04"
                }
            ],
            "source": "CPE_FIELD"
        },
        {
            "cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "18.04"
                }
            ],
            "source": "CPE_FIELD"
        },
        {
            "cpe": "cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "19.10"
                }
            ],
            "source": "CPE_FIELD"
        },
        {
            "cpe": "cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "30"
                }
            ],
            "source": "CPE_FIELD"
        },
        {
            "cpe": "cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "31"
                }
            ],
            "source": "CPE_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/python-pillow/pillow

Affected ranges

Type
GIT
Repo
https://github.com/python-pillow/pillow
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "6.2.2"
        }
    ],
    "source": [
        "CPE_FIELD",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.0
1.2
1.7.7
1.7.8
2.*
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.5.0
2.7.0
2.8.0
2.8.1
2.9.0
2.9.0.dev0
2.9.0.dev1
2.9.0.dev2
3.*
3.1.0
3.1.0-rc1
3.2.0
3.3.0
3.4.0
4.*
4.0.0
4.0.0a
4.1.0
4.2.0
4.3.0
5.*
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
6.*
6.0.0
6.1.0
6.2.0
6.2.1

Database specific

vanir_signatures
[
    {
        "target": {
            "file": "src/libImaging/TiffDecode.c"
        },
        "id": "CVE-2020-5310-dd6ea137",
        "signature_version": "v1",
        "deprecated": false,
        "source": "https://github.com/python-pillow/pillow/commit/4e2def2539ec13e53a82e06c4b3daf00454100c4",
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "11063566985366830361541805365964257484",
                "10227853089858799829606132986670377937",
                "317038433496737873798409669386881171228",
                "117583418836728761439750076620579841509",
                "42548093785476519379886330909429997892",
                "180296352043842206907328859036068743446",
                "232392863528886449003010581525191622890",
                "170708454611785382970649880980374429778",
                "194205829702377816602101179673064497694",
                "233404740975746542367800271115279682632",
                "263102630687762320497076038078445684335",
                "195294903843144035227280250434198303035",
                "31124841263578157110148021800467585987",
                "310907908465319355122623942791978593816",
                "339390408024927267804818065141722014459"
            ]
        }
    },
    {
        "target": {
            "function": "ImagingLibTiffDecode",
            "file": "src/libImaging/TiffDecode.c"
        },
        "id": "CVE-2020-5310-ebcc8c54",
        "signature_version": "v1",
        "deprecated": false,
        "source": "https://github.com/python-pillow/pillow/commit/4e2def2539ec13e53a82e06c4b3daf00454100c4",
        "signature_type": "Function",
        "digest": {
            "function_hash": "56824892614320334599794661287660083213",
            "length": 4897.0
        }
    }
]
vanir_signatures_modified
"2026-04-12T00:01:42Z"
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-5310.json"