Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python-pillow-develUpgrade python-pillow-tkUpgrade python-pillow-saneUpgrade python-pillow-debuginfoUpgrade python-pillow-docUpgrade python-pillow | Jun 8, 2023 | Nov 4, 2016 |
| Amazon_linux | — | Upgrade python-imaging | Jul 20, 2023 | Nov 4, 2016 |
| Debian | — | Upgrade python-imagingUpgrade pillow | Nov 11, 2016 | Nov 4, 2016 |
| Freebsd | — | Upgrade py35-pillowUpgrade py34-pillowUpgrade py27-pillowUpgrade py33-pillow | Dec 4, 2016 | Dec 4, 2016 |
| Gentoo Linux | — | Upgrade dev-python/pillow. | Oct 30, 2017 | Nov 4, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade python-pillow | Nov 30, 2017 | Nov 4, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade python-pillow | Dec 4, 2019 | Nov 4, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade python-pillow | Dec 18, 2019 | Nov 4, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade python-pillow | Jul 2, 2019 | Nov 4, 2016 |
| Oracle Solaris | — | Upgrade library/python/python-imaging-27 to version 1.1.7-0.175.3.15.0.4.0 on Solaris 11.3Upgrade library/python/python-imaging-26 to version 1.1.7-0.175.3.15.0.4.0 on Solaris 11.3Upgrade library/python/python-imaging to version 1.1.7-0.175.3.15.0.4.0 on Solaris 11.3 | May 29, 2017 | Nov 4, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 3, 2016 |
| Ubuntu | — | Upgrade python-imagingUpgrade python-pilUpgrade python3-imagingUpgrade python3-pil | Mar 14, 2017 | Nov 4, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub