Lucene search

K
cvelistMitreCVELIST:CVE-2020-35654
HistoryJan 12, 2021 - 8:06 a.m.

CVE-2020-35654

2021-01-1208:06:55
mitre
www.cve.org
8
pillow
tiffdecode
heap-based buffer overflow
ycbcr files
libtiff
rgba mode

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

60.5%

In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.