libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
{ "vanir_signatures": [ { "signature_version": "v1", "digest": { "length": 3419.0, "function_hash": "302220455464486737318526284033412250665" }, "source": "https://github.com/python-pillow/pillow/commit/a09acd0decd8a87ccce939d5ff65dab59e7d365b", "deprecated": false, "target": { "file": "src/libImaging/FliDecode.c", "function": "ImagingFliDecode" }, "signature_type": "Function", "id": "CVE-2020-5313-b532e49c" }, { "signature_version": "v1", "digest": { "threshold": 0.9, "line_hashes": [ "37157442833106023353193678460912189837", "270660893983846785194614299295365101477", "123429680817191715397250062351088262009", "80828568724056570888061163794266956490", "200114137639258668432822712228387541758", "60017815867957894917657944409302113715" ] }, "source": "https://github.com/python-pillow/pillow/commit/a09acd0decd8a87ccce939d5ff65dab59e7d365b", "deprecated": false, "target": { "file": "src/libImaging/FliDecode.c" }, "signature_type": "Line", "id": "CVE-2020-5313-d95c34be" } ] }