#VU23910 Integer overflow in Pillow - CVE-2020-5310
Published: January 3, 2020
Pillow
Alex Clark and Contributors
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to TIFF decoding integer overflow in "libImaging/TiffDecode.c". A remote attacker can trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.