Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk: Low] Pillow Out-of-bounds Read (6/2/21) #4443

Closed
hcaofec opened this issue Mar 3, 2021 · 2 comments
Closed

[Snyk: Low] Pillow Out-of-bounds Read (6/2/21) #4443

hcaofec opened this issue Mar 3, 2021 · 2 comments
Labels
Security: low Remediate within 90 days

Comments

@hcaofec
Copy link
Contributor

hcaofec commented Mar 3, 2021

@hcaofec commented on Wed Mar 03 2021

Introduced through: pillow@7.1.0 and wagtail@2.7.4
Exploit maturity: NO KNOWN EXPLOIT

Detailed paths
Introduced through: project@0.0.0 › pillow@7.1.0
Remediation: No remediation path available.
Introduced through: project@0.0.0 › wagtail@2.7.4 › Pillow@7.1.0
Remediation: No remediation path available.
Overview
Pillow is a PIL (Python Imaging Library) fork.

Affected versions of this package are vulnerable to Out-of-bounds Read due to invalid tile boundaries lead.

More info:
https://app.snyk.io/vuln/SNYK-PYTHON-PILLOW-1080635

@patphongs
Copy link
Member

This package does not cause a significant external security vulnerability since only approved and authenticated Wagtail users can upload resources to our system. We plan to patch this package when we upgrade our Wagtail version to the latest 2.11 LTS.

@patphongs patphongs changed the title [Snyk: High] Pillow Out-of-bounds Read (4/2/21) [Snyk: High] Pillow Out-of-bounds Read (6/2/21) Mar 4, 2021
@patphongs patphongs changed the title [Snyk: High] Pillow Out-of-bounds Read (6/2/21) [Snyk: Low] Pillow Out-of-bounds Read (6/2/21) Mar 4, 2021
@patphongs patphongs added the Security: low Remediate within 90 days label Mar 4, 2021
@patphongs
Copy link
Member

No longer flagged

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Security: low Remediate within 90 days
Projects
None yet
Development

No branches or pull requests

2 participants