First published: Tue Mar 29 2016(Updated: )
Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Python Pillow | =2.5.0 | |
Python Pillow | =2.5.1 | |
Python Pillow | =2.5.2 | |
Python Pillow | =2.5.3 | |
Python Pillow | =2.6.0 | |
Python Pillow | =2.6.0-rc1 | |
Python Pillow | =2.6.1 | |
Python Pillow | =2.6.2 | |
Python Pillow | =2.7.0 | |
Python Pillow | =2.8.0 | |
Python Pillow | =2.8.1 | |
Python Pillow | =2.8.2 | |
Python Pillow | =2.9.0 | |
Python Pillow | =2.9.0-dev0 | |
Python Pillow | =2.9.0-dev1 | |
Python Pillow | =2.9.0-dev2 | |
Python Pillow | =3.0.0 | |
Python Pillow | =3.0.0-rc1 | |
Python Pillow | =3.1.0 | |
pip/pillow | >=2.5.0<3.1.2 | 3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.