PT-2016-5191 · Python+1 · Pillow+2

Published

2016-02-28

·

Updated

2020-05-06

·

CVE-2016-2533

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Pillow versions prior to 3.1.1 Python Imaging Library (PIL) version 1.1.7 and earlier
Description The issue is related to a buffer overflow in the ImagingPcdDecode function, which can be triggered by a crafted PhotoCD file, allowing remote attackers to cause a denial of service (crash).
Recommendations For Pillow versions prior to 3.1.1, update to version 3.1.1 or later to resolve the issue. For Python Imaging Library (PIL) version 1.1.7 and earlier, update to a version later than 1.1.7 to resolve the issue. As a temporary workaround, consider disabling the use of the ImagingPcdDecode function in PcdDecode.c until a patch is available.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-2533
DLA-422-1
DSA-3499-1
GHSA-3C5C-7235-994J
PYSEC-2016-19
SUSE-SU-2019:2334-1
SUSE-SU-2020:1194-1
USN-3080-1
USN-3090-1

Affected Products

Pillow
Python Imaging Library
Ubuntu