Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python-pillow-docUpgrade python-pillow-debuginfoUpgrade python-pillowUpgrade python-pillow-develUpgrade python-pillow-tkUpgrade python-pillow-sane | Mar 26, 2025 | Apr 13, 2016 |
| Debian | — | Upgrade python-imagingUpgrade pillow | Feb 29, 2016 | Feb 28, 2016 |
| Gentoo Linux | — | Upgrade dev-python/pillow. | Oct 30, 2017 | Apr 13, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade python-pillow | Dec 4, 2019 | Apr 13, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade python-pillow | Dec 18, 2019 | Apr 13, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade python-pillow | Nov 19, 2019 | Apr 13, 2016 |
| Oracle Solaris | — | Upgrade library/python/python-imaging-27 to version 1.1.7-0.175.3.6.0.3.0 on Solaris 11.3Upgrade library/python/python-imaging to version 1.1.7-0.175.3.6.0.3.0 on Solaris 11.3Upgrade library/python/python-imaging-26 to version 1.1.7-0.175.3.6.0.3.0 on Solaris 11.3 | May 29, 2017 | Apr 13, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 24, 2014 |
| Ubuntu | — | Upgrade python3-imagingUpgrade python-pilUpgrade python-imagingUpgrade python3-pil | Sep 15, 2016 | Apr 13, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub