{"id":"CVE-2020-11538","aliases":["BIT-pillow-2020-11538","GHSA-43fq-w8qq-v88h","PYSEC-2020-80"],"url":"https://o3.security/vulnerability/CVE-2020-11538","summary":"Out-of-bounds read in Pillow","details":"In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.","published":"2020-06-25T19:15:12.537Z","modified":"2026-08-07T11:31:17.047612012Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"pillow","fixedVersion":"7.1.0"}],"fix":{"url":"https://github.com/python-pillow/Pillow/pull/4504","label":"python-pillow/Pillow#4504"},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEBCPE4F2VHTIT6EZA2YZQZLPVDEBJGD/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HOKHNWV2VS5GESY7IBD237E7C6T3I427/"},{"type":"WEB","url":"https://pillow.readthedocs.io/en/stable/releasenotes/7.1.0.html"},{"type":"ADVISORY","url":"https://pillow.readthedocs.io/en/stable/releasenotes/index.html"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4430-1/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4430-2/"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/4504"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/4538"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:17.047612012Z"}}