CVE-2016-9189: Integer Overflow
Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.mapbuffer in map.c component.
Other sources
Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.mapbuffer in map.c component.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9189?
CVE-2016-9189 has been classified as a medium severity vulnerability.
How do I fix CVE-2016-9189?
To fix CVE-2016-9189, upgrade Pillow to version 3.3.2 or later.
What types of attacks are possible with CVE-2016-9189?
CVE-2016-9189 allows context-dependent attackers to obtain sensitive information via crafted image files.
Which versions of Pillow are affected by CVE-2016-9189?
Pillow versions before 3.3.2 are affected by CVE-2016-9189.
What components are impacted by CVE-2016-9189?
CVE-2016-9189 impacts the `Image.core.map_buffer` within the `map.c` component.