FlawAtlas
Search the atlas
SUSE-SU-2018:1174-1 Not scored

Security update for python-Pillow

This update for python-Pillow fixes the following issues: * CVE-2016-9190: Pillow allows context-dependent attackers to execute arbitrary code by using the \'crafted image file\' approach, related to an \'Insecure Sign Extension\' issue affecting the ImagingNew in Storage.c component. (bsc#1008846) * CVE-2016-3076: Heap-based buffer overflow in the j2k_encode_entry function allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file. (bsc#973786)

Exploit probability Not scored
Published May 8, 2018
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 4 python-Pillow
SUSE:OpenStack Cloud 7 python-Pillow

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2018:1174-1

This update for python-Pillow fixes the following issues: * CVE-2016-9190: Pillow allows context-dependent attackers to execute arbitrary code by using the \'crafted image file\' approach, related to an \'Insecure Sign Extension\' issue affecting the ImagingNew in Storage.c component. (bsc#1008846) * CVE-2016-3076: Heap-based buffer overflow in the j2k_encode_entry function allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file. (bsc#973786)

View original source

05 / REFERENCES

Further evidence