ZeroHour

CVE-2016-9190

CVSS 3.0
7.8 high
EPSS
2%p78
Published
()
Modified
Description

Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.

Vendors
pythondebian
Products
pillow, debian linux
Weakness
CWE-284
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.