libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
[
    {
        "deprecated": false,
        "source": "https://github.com/python-pillow/pillow/commit/a79b65c47c7dc6fe623aadf09aa6192fc54548f3",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "74394628443402872264910573382191555015",
                "331322978970584824777287696594234124122",
                "23182711350509848214109658018129134498",
                "21295675298201514072661238004526791439",
                "147362313223325050429672845411114095032",
                "11728680069999553532564805891395609734",
                "146542584084456442475866787063765149690",
                "111995761264553157563801106692361300122",
                "336894040779789205909693731782617387270",
                "282092743345704169374304954216301115022",
                "169513242581767477544127227679857517673",
                "64785095045983690514758407603369230022",
                "147362313223325050429672845411114095032",
                "11728680069999553532564805891395609734",
                "146542584084456442475866787063765149690",
                "125630191536919897373952870166590578771",
                "58373006746695298486896448352276165673",
                "335858634260284363779854828498007781985",
                "109186713654740590875643673206751540586",
                "252524666320560104270511936646063661420",
                "228363093971994857844065892422863375425",
                "220845418040944005946317753051840329161",
                "24059358200304628671709782237977515221",
                "175644003446321522865613307084547865669",
                "186816661014658657970488018787100125892",
                "84551653920536917952441927246021476869",
                "246616666101419533298827601867129363327",
                "284404479206762129323202108270234175513",
                "116356111928500685543966321177907648373"
            ]
        },
        "target": {
            "file": "src/libImaging/SgiRleDecode.c"
        },
        "id": "CVE-2020-5311-655a3b71",
        "signature_version": "v1",
        "signature_type": "Line"
    },
    {
        "deprecated": false,
        "source": "https://github.com/python-pillow/pillow/commit/a79b65c47c7dc6fe623aadf09aa6192fc54548f3",
        "digest": {
            "function_hash": "23537580919283434488848292199174173919",
            "length": 503.0
        },
        "target": {
            "function": "expandrow2",
            "file": "src/libImaging/SgiRleDecode.c"
        },
        "id": "CVE-2020-5311-7b789c14",
        "signature_version": "v1",
        "signature_type": "Function"
    },
    {
        "deprecated": false,
        "source": "https://github.com/python-pillow/pillow/commit/a79b65c47c7dc6fe623aadf09aa6192fc54548f3",
        "digest": {
            "function_hash": "189928262583536917268053492207105390628",
            "length": 441.0
        },
        "target": {
            "function": "expandrow",
            "file": "src/libImaging/SgiRleDecode.c"
        },
        "id": "CVE-2020-5311-df88ec3e",
        "signature_version": "v1",
        "signature_type": "Function"
    },
    {
        "deprecated": false,
        "source": "https://github.com/python-pillow/pillow/commit/a79b65c47c7dc6fe623aadf09aa6192fc54548f3",
        "digest": {
            "function_hash": "48429839654790430206881399079807026749",
            "length": 2942.0
        },
        "target": {
            "function": "ImagingSgiRleDecode",
            "file": "src/libImaging/SgiRleDecode.c"
        },
        "id": "CVE-2020-5311-e7784fba",
        "signature_version": "v1",
        "signature_type": "Function"
    }
]