CVE-2016-9190: High severity python imaging library (pillow) vulnerability
Published Nov 4, 2016
·Updated
Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.
Affected Software
3 affected componentsFixes available
pip/Pillow<3.3.2
3.3.2
Python Pillow<=3.3.1
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Nov 4, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Jul 12, 2018
Advisory Published
via GitHub·02:45 PM
Frequently Asked Questions
1
What is the severity of CVE-2016-9190?
CVE-2016-9190 is rated as moderate severity due to its potential for arbitrary code execution.
2
How do I fix CVE-2016-9190?
To fix CVE-2016-9190, upgrade to Pillow version 3.3.2 or later.
3
What is the impact of CVE-2016-9190?
CVE-2016-9190 allows context-dependent attackers to execute arbitrary code via crafted image files.
4
Which versions of Pillow are affected by CVE-2016-9190?
Versions of Pillow prior to 3.3.2 are affected by CVE-2016-9190.
5
Is CVE-2016-9190 specific to any operating systems?
CVE-2016-9190 can affect systems using Pillow before version 3.3.2, including platforms like Debian.