Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python-pillow-debuginfoUpgrade python-pillow-saneUpgrade python-pillow-docUpgrade python-pillow-tkUpgrade python-pillowUpgrade python-pillow-devel | Jan 10, 2024 | Nov 4, 2016 |
| Debian | — | Upgrade pillowUpgrade python-imaging | Nov 11, 2016 | Nov 4, 2016 |
| Freebsd | — | Upgrade py34-pillowUpgrade py35-pillowUpgrade py33-pillowUpgrade py27-pillow | Dec 4, 2016 | Dec 4, 2016 |
| Gentoo Linux | — | Upgrade dev-python/pillow. | Oct 30, 2017 | Nov 4, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade python-pillow | Dec 4, 2019 | Nov 4, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade python-pillow | Dec 18, 2019 | Nov 4, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade python-pillow | Nov 19, 2019 | Nov 4, 2016 |
| Oracle Solaris | — | Upgrade library/python/python-imaging-27 to version 1.1.7-0.175.3.15.0.4.0 on Solaris 11.3Upgrade library/python/python-imaging to version 1.1.7-0.175.3.15.0.4.0 on Solaris 11.3Upgrade library/python/python-imaging-26 to version 1.1.7-0.175.3.15.0.4.0 on Solaris 11.3 | May 29, 2017 | Nov 4, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 3, 2016 |
| Ubuntu | — | Upgrade python-pilUpgrade python3-pilUpgrade python3-imagingUpgrade python-imaging | Mar 14, 2017 | Nov 4, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub