libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
{ "urgency": "not yet assigned" }