Out-of-bounds read In pillow

Description

Out-of-bounds reads in Pillow Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions

References

1. https://github.com/python-pillow/Pillow/issues/47502. https://github.com/python-pillow/Pillow/pull/45033. https://github.com/python-pillow/Pillow/pull/45384. https://github.com/python-pillow/Pillow/commit/f6926a041b4b544fd2ced3752542afb6c8c194055. https://github.com/python-pillow/Pillow/commit/c88b0204d7c930e3bd72626ae6ea078571cc0ea76. https://github.com/python-pillow/Pillow/commit/c66d8aa75436f334f686fe32bca8e414bcdd18e67. https://github.com/python-pillow/Pillow/commit/c5edc361fd6450f805a6a444723b0f68190b1d0c8. https://github.com/python-pillow/Pillow/commit/b4e439d6d7fd986cd6b4c7f9ca18830d79dacd449. https://github.com/python-pillow/Pillow/commit/8d4f3c0c5f2fecf175aeb895e9c2d6d06d85bdc910. https://github.com/python-pillow/Pillow/commit/5b490fc413dfab2d52de46a58905c25d9badb65011. https://github.com/python-pillow/Pillow/commit/19ff42bd683486a8a308743c76972ef6a6482e9b12. https://github.com/python-pillow/Pillow/commit/11ef7ca53a7d0af4bc52666c29199deffa5fc1bd13. https://github.com/python-pillow/Pillow/commit/088ce4df981b70fbec140ee54417bcb49a7dffca14. https://github.com/python-pillow/Pillow/commit/00c6dd72d9ed0124cec81040b4bab0979a200fe215. https://pillow.readthedocs.io/en/stable/releasenotes/6.2.3.html16. https://lists.fedoraproject.org/archives/list/[email protected]/message/HOKHNWV2VS5GESY7IBD237E7C6T3I42717. https://pillow.readthedocs.io/en/stable/releasenotes/7.1.0.html18. https://usn.ubuntu.com/4430-119. https://usn.ubuntu.com/4430-220. https://lists.fedoraproject.org/archives/list/[email protected]/message/BEBCPE4F2VHTIT6EZA2YZQZLPVDEBJGD21. https://github.com/python-pillow/Pillow/commits/master/src/libImaging22. https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2020-76.yaml