libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
[
{
"id": "CVE-2020-5313-b532e49c",
"deprecated": false,
"target": {
"function": "ImagingFliDecode",
"file": "src/libImaging/FliDecode.c"
},
"source": "https://github.com/python-pillow/pillow/commit/a09acd0decd8a87ccce939d5ff65dab59e7d365b",
"digest": {
"length": 3419.0,
"function_hash": "302220455464486737318526284033412250665"
},
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2020-5313-d95c34be",
"deprecated": false,
"target": {
"file": "src/libImaging/FliDecode.c"
},
"source": "https://github.com/python-pillow/pillow/commit/a09acd0decd8a87ccce939d5ff65dab59e7d365b",
"digest": {
"line_hashes": [
"37157442833106023353193678460912189837",
"270660893983846785194614299295365101477",
"123429680817191715397250062351088262009",
"80828568724056570888061163794266956490",
"200114137639258668432822712228387541758",
"60017815867957894917657944409302113715"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line"
}
]