VYPR
High severity8.8NVD Advisory· Published Jan 3, 2020· Updated Jun 17, 2026

CVE-2020-5310

CVE-2020-5310

Description

libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
pillowPyPI
< 6.2.26.2.2

Affected products

10
  • Pillow/Pillowdescription
  • cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*
    Range: <6.2.2
  • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*+ 3 more
    • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
  • ghsa-coords2 versions
    < 6.2.2+ 1 more
    • (no CPE)range: < 6.2.2
    • (no CPE)range: < 6.2.2

Patches

Vulnerability mechanics

References

12

News mentions

0

No linked articles in our index yet.