VDB
Sign up
—

PYSEC-2016-19

Quick fix

PYSEC-2016-19 — pillow: upgrade to the fixed version with the command below.

pip install --upgrade 'pillow>=5bdf54b5a76b54fb00bd05f2d733e0a4173eefc9'

Details

Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pillow
Introduced in: 0Fixed in: 5bdf54b5a76b54fb00bd05f2d733e0a4173eefc9
Fixpip install --upgrade 'pillow>=5bdf54b5a76b54fb00bd05f2d733e0a4173eefc9'

References