CVE-2016-0740: Buffer Overflow
Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.
Other sources
Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0740?
CVE-2016-0740 is considered a high severity vulnerability due to the potential for remote code execution through a crafted TIFF file.
How do I fix CVE-2016-0740?
To fix CVE-2016-0740, upgrade Pillow to version 3.1.1 or later.
Which versions of Pillow are affected by CVE-2016-0740?
Pillow versions prior to 3.1.1 are affected by CVE-2016-0740.
Can CVE-2016-0740 be exploited remotely?
Yes, CVE-2016-0740 can be exploited remotely via crafted TIFF files.
What components are affected by CVE-2016-0740?
CVE-2016-0740 affects the ImagingLibTiffDecode function in the libImaging/TiffDecode.c file of Pillow.