CVE-2016-9190
04.11.2016, 10:59
Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| python | pillow | 𝑥 ≤ 3.3.1 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| python-imaging-debuginfo |
| ||
| python-pillow |
| ||
| python-pillow-debuginfo |
| ||
| python-pillow-devel |
| ||
| python-pillow-doc |
| ||
| python-pillow-sane |
| ||
| python-pillow-tk |
| ||
| python26-imaging |
| ||
| python26-imaging-devel |
| ||
| python27-imaging |
| ||
| python27-imaging-devel |
|
Common Weakness Enumeration
References