Bugzilla – Bug 1008846
VUL-0: CVE-2016-9190: python-pillow: Missing check for negative image dimensions in ImagingNew (Storage.c)
Last modified: 2019-05-23 22:39:20 UTC
rh#1382006 Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component. References: https://bugzilla.redhat.com/show_bug.cgi?id=1382006 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9190 http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-9190.html http://www.cvedetails.com/cve/CVE-2016-9190/ https://github.com/python-pillow/Pillow/pull/2146/commits/5d8a0be45aad78c5a22c8d099118ee26ef8144af
bugbot adjusting priority
Cloud 6 and 7 affected
https://trello.com/c/mWIcZC1j
For Ocata https://build.opensuse.org/request/show/591748 , though nobody should be using this. For Newton https://build.opensuse.org/request/show/591746 , waiting for this to copy it to Devel:Cloud:7 so it can become https://build.suse.de/package/show/SUSE:SLE-12-SP2:Update:Products:Cloud7:Update/python-Pillow .
SOC6: https://build.suse.de/request/show/160676
SUSE-SU-2018:1174-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1008846,973786 CVE References: CVE-2016-3076,CVE-2016-9190 Sources used: SUSE OpenStack Cloud 7 (src): python-Pillow-2.8.1-4.3.2 SUSE Enterprise Storage 4 (src): python-Pillow-2.8.1-4.3.2
SUSE-SU-2018:1191-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1008846,973786 CVE References: CVE-2016-3076,CVE-2016-9190 Sources used: SUSE OpenStack Cloud 6 (src): python-Pillow-2.7.0-4.3.1
fixed
SUSE-SU-2019:1321-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1008845,1008846,973786 CVE References: CVE-2016-3076,CVE-2016-9189,CVE-2016-9190 Sources used: SUSE Enterprise Storage 5 (src): python-Pillow-2.8.1-3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.