libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.
[
{
"id": "CVE-2020-5310-dd6ea137",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"11063566985366830361541805365964257484",
"10227853089858799829606132986670377937",
"317038433496737873798409669386881171228",
"117583418836728761439750076620579841509",
"42548093785476519379886330909429997892",
"180296352043842206907328859036068743446",
"232392863528886449003010581525191622890",
"170708454611785382970649880980374429778",
"194205829702377816602101179673064497694",
"233404740975746542367800271115279682632",
"263102630687762320497076038078445684335",
"195294903843144035227280250434198303035",
"31124841263578157110148021800467585987",
"310907908465319355122623942791978593816",
"339390408024927267804818065141722014459"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://github.com/python-pillow/pillow/commit/4e2def2539ec13e53a82e06c4b3daf00454100c4",
"target": {
"file": "src/libImaging/TiffDecode.c"
}
},
{
"id": "CVE-2020-5310-ebcc8c54",
"signature_version": "v1",
"digest": {
"length": 4897.0,
"function_hash": "56824892614320334599794661287660083213"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://github.com/python-pillow/pillow/commit/4e2def2539ec13e53a82e06c4b3daf00454100c4",
"target": {
"file": "src/libImaging/TiffDecode.c",
"function": "ImagingLibTiffDecode"
}
}
]