Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| pillow(PyPI) | 2.5.0 | 3.1.2 | N/A |
CVSS Metrics