Potential buffer overflow in psd-tools
Critical severity
GitHub Reviewed
Published
Mar 16, 2020
in
psd-tools/psd-tools
•
Updated Oct 21, 2024
Description
Reviewed
Mar 16, 2020
Published to the GitHub Advisory Database
Mar 16, 2020
Last updated
Oct 21, 2024
Impact
An issue was discovered in psd-tools before 1.9.4. The Cython implementation of RLE decoding did not check for malformed PSD input data during decoding to the PIL.Image or NumPy format, leading to a Buffer Overflow.
Patches
Users of psd-tools version v1.8.37 to v1.9.3 should upgrade to v1.9.4.
Workarounds
Without Cython present on installation, buffer overflow does not occur but IndexError will be thrown. However, already installed psd-tools with Cython extention should be upgraded.
References
psd-tools/psd-tools#198
For more information
If you have any questions or comments about this advisory:
References