VDB
KO

PYSEC-2020-79

Details

In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / pillow
Introduced in: 0 Fixed in: 7.0.0
Fix pip install --upgrade 'pillow>=7.0.0'

References