Improper authorization control for web services In pillow
Description
Arbitrary code using "crafted image file" approach affecting Pillow Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 3.3.2 | ||
debian 14 | 3.4.2-1 | ||
debian 11 | 3.4.2-1 | ||
debian 12 | 3.4.2-1 | ||
rpm rhel6 | - | - | |
debian 13 | 3.4.2-1 | ||
rpm rhel7 | - | - | |
rpm rhel5 | - | - |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2. 3. 4. 5. 6.