Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9190

Опубликовано: 04 нояб. 2016
Источник: debian

Описание

Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pillowfixed3.4.2-1package
python-imagingremovedpackage

Примечания

  • https://github.com/python-pillow/Pillow/issues/2105

  • https://github.com/python-pillow/Pillow/pull/2146/commits/5d8a0be45aad78c5a22c8d099118ee26ef8144af

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 9 лет назад

Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.

CVSS3: 7.3
redhat
больше 9 лет назад

Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.

CVSS3: 7.8
nvd
больше 9 лет назад

Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.

CVSS3: 7.8
github
больше 7 лет назад

Arbitrary code using "crafted image file" approach affecting Pillow