Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python-pillow-saneUpgrade python-pillow-debuginfoUpgrade python-pillowUpgrade python-pillow-tkUpgrade python-pillow-develUpgrade python-pillow-doc | Jan 10, 2024 | Nov 4, 2016 |
| Debian | — | Upgrade python-imagingUpgrade pillow | Nov 11, 2016 | Nov 4, 2016 |
| Freebsd | — | Upgrade py33-pillowUpgrade py27-pillowUpgrade py34-pillowUpgrade py35-pillow | Dec 4, 2016 | Dec 4, 2016 |
| Gentoo Linux | — | Upgrade dev-python/pillow. | Oct 30, 2017 | Nov 4, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade python-pillow | Dec 4, 2019 | Nov 4, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade python-pillow | Dec 18, 2019 | Nov 4, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade python-pillow | Nov 19, 2019 | Nov 4, 2016 |
| Oracle Solaris | — | Upgrade library/python/python-imaging to version 1.1.7-0.175.3.15.0.4.0 on Solaris 11.3Upgrade library/python/python-imaging-27 to version 1.1.7-0.175.3.15.0.4.0 on Solaris 11.3Upgrade library/python/python-imaging-26 to version 1.1.7-0.175.3.15.0.4.0 on Solaris 11.3 | May 29, 2017 | Nov 4, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 3, 2016 |
| Ubuntu | — | Upgrade python-imagingUpgrade python3-imagingUpgrade python-pilUpgrade python3-pil | Mar 14, 2017 | Nov 4, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub