Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-9190

Опубликовано: 04 нояб. 2016
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 7.8

Описание

Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.

РелизСтатусПримечание
devel

not-affected

4.0.0-4
esm-infra-legacy/trusty

released

2.3.0-1ubuntu3.4
esm-infra/xenial

released

3.1.2-0ubuntu1.1
precise

DNE

trusty

released

2.3.0-1ubuntu3.4
trusty/esm

released

2.3.0-1ubuntu3.4
upstream

released

3.3.2
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

released

3.1.2-0ubuntu1.1

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

precise

released

1.1.7-4ubuntu0.12.04.3
trusty

DNE

trusty/esm

DNE

upstream

needs-triage

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

DNE

yakkety

DNE

Показывать по

EPSS

Процентиль: 68%
0.00566
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
redhat
больше 9 лет назад

Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.

CVSS3: 7.8
nvd
больше 9 лет назад

Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.

CVSS3: 7.8
debian
больше 9 лет назад

Pillow before 3.3.2 allows context-dependent attackers to execute arbi ...

CVSS3: 7.8
github
больше 7 лет назад

Arbitrary code using "crafted image file" approach affecting Pillow

EPSS

Процентиль: 68%
0.00566
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3