Out-of-bounds read In pillow
Description
Pillow Integer overflow in Map.c
Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 3.3.2 | ||
debian 12 | 3.4.2-1 | ||
debian 11 | 3.4.2-1 | ||
debian 13 | 3.4.2-1 | ||
debian 14 | 3.4.2-1 | ||
rpm rhel6 | - | - | |
rpm rhel5 | - | - | |
rpm rhel7 | - | - |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2. 3. 4. 5. 6. 7.