Pillow before 6.2.3 and 7.x before 7.0.1 has multiple out-of-bounds reads in libImaging/FliDecode.c. Pull Request: https://github.com/python-pillow/Pillow/pull/4538 Upstream Advisory: https://pillow.readthedocs.io/en/stable/releasenotes/7.1.0.html Upstream Advisory: https://pillow.readthedocs.io/en/stable/releasenotes/6.2.3.html