An issue was discovered in psd-tools before 1.9.4. The Cython implementation of RLE decoding did not check for malicious data.
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
Link | Tags |
---|---|
https://github.com/psd-tools/psd-tools/pull/198 | third party advisory patch |
https://github.com/psd-tools/psd-tools/releases/tag/v1.9.4 | third party advisory release notes |