VDB

PYSEC-2016-9

PYSEC-2016-9 PUBLISHED CVSS 9.300000190734863 CRITICAL

Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
PyPIpillow0, 1.0, 1.1

Timeline

  • Nov 4, 2016 CVE Published
  • Nov 8, 2023 CVE Updated
  • May 18, 2026 Distribution Patch
  • May 18, 2026 Security Advisory
  • May 18, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›