libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
{ "vanir_signatures": [ { "signature_version": "v1", "digest": { "length": 1273.0, "function_hash": "228195334488469053776152312293290694292" }, "id": "CVE-2020-5312-ac16992a", "deprecated": false, "target": { "file": "src/libImaging/PcxDecode.c", "function": "ImagingPcxDecode" }, "signature_type": "Function", "source": "https://github.com/python-pillow/pillow/commit/93b22b846e0269ee9594ff71a72bec02d2bea8fd" }, { "signature_version": "v1", "digest": { "threshold": 0.9, "line_hashes": [ "28176007691574792831032194145824532472", "60039019189674651359812065381069837303", "70280912336820827533766265349563168504", "137238534060640963082355829647107153874" ] }, "id": "CVE-2020-5312-b19af775", "deprecated": false, "target": { "file": "src/libImaging/PcxDecode.c" }, "signature_type": "Line", "source": "https://github.com/python-pillow/pillow/commit/93b22b846e0269ee9594ff71a72bec02d2bea8fd" } ] }