CVE-2016-0740
published 2016-04-13CVE-2016-0740: Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a…
PriorityP431medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
2.36%
81.9th percentile
Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | pillow | < pillow 3.1.1-1 (bookworm) | pillow 3.1.1-1 (bookworm) |
| python | pillow | <= 3.1.0 | — |
| python | pillow | >= 0 < 3.1.1-1 | 3.1.1-1 |
| python | pillow | >= 0 < 3.1.1-1 | 3.1.1-1 |
| python | pillow | >= 0 < 3.1.1-1 | 3.1.1-1 |
| python | pillow | >= 0 < 3.1.1-1 | 3.1.1-1 |
| python | pillow | >= 0 < 3.1.1 | 3.1.1 |
| python | pillow | >= 0 < 2.3.0-1ubuntu3.3 | 2.3.0-1ubuntu3.3 |
| python | pillow | >= 0 < 2.3.0-1ubuntu3.2 | 2.3.0-1ubuntu3.2 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Pillow Buffer overflow in ImagingLibTiffDecode
ghsa·2018-07-24
CVE-2016-0740 [MEDIUM] CWE-119 Pillow Buffer overflow in ImagingLibTiffDecode
Pillow Buffer overflow in ImagingLibTiffDecode
Buffer overflow in the `ImagingLibTiffDecode` function in `libImaging/TiffDecode.c` in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.
OSV
Pillow Buffer overflow in ImagingLibTiffDecode
osv·2018-07-24
CVE-2016-0740 [MEDIUM] Pillow Buffer overflow in ImagingLibTiffDecode
Pillow Buffer overflow in ImagingLibTiffDecode
Buffer overflow in the `ImagingLibTiffDecode` function in `libImaging/TiffDecode.c` in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.
OSV
Pillow regression
osv·2016-09-30·CVSS 5.0
CVE-2014-9601 [MEDIUM] Pillow regression
Pillow regression
USN-3090-1 fixed vulnerabilities in Pillow. The patch to fix CVE-2014-9601
caused a regression which resulted in failures when processing certain
png images. This update temporarily reverts the security fix for CVE-2014-9601
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorrectly handled certain malformed
FLI,
OSV
Pillow vulnerabilities
osv·2016-09-27·CVSS 5.0
CVE-2014-9601 [MEDIUM] Pillow vulnerabilities
Pillow vulnerabilities
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorrectly handled certain malformed
FLI, Tiff, and PhotoCD files. A remote attacker could use this issue to
cause Pillow to crash, resulting in a denial of service.
(CVE-2016-0740, CVE-2016-0775, CVE-2016-2533)
OSV
CVE-2016-0740: Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode
osv·2016-04-13·CVSS 6.5
CVE-2016-0740 [MEDIUM] CVE-2016-0740: Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode
Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.
Ubuntu
Pillow regresssion
vendor_ubuntu·2016-09-30·CVSS 5.0
CVE-2014-9601 [MEDIUM] Pillow regresssion
Title: Pillow regresssion
Summary: Pillow regresssion
USN-3090-1 fixed vulnerabilities in Pillow. The patch to fix CVE-2014-9601
caused a regression which resulted in failures when processing certain
png images. This update temporarily reverts the security fix for CVE-2014-9601
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorr
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2016-09-27·CVSS 5.0
CVE-2014-3589 [MEDIUM] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Pillow could be made to crash if it received specially crafted input or opened
a specially crafted file.
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorrectly handled certain malformed
FLI, Tiff, and PhotoCD files. A remote attacker could use this issue to
cause Pillow to crash, resulting in a denial of service.
(CVE-2016-0740, CVE-2016-0775, CVE-2016-2533)
Instructions: In general
Red Hat
python-pillow: Integer overflow resulting in buffer overflow when reading invalid tiff file
vendor_redhat·2016-02-04·CVSS 6.5
CVE-2016-0740 [MEDIUM] CWE-190 python-pillow: Integer overflow resulting in buffer overflow when reading invalid tiff file
python-pillow: Integer overflow resulting in buffer overflow when reading invalid tiff file
Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.
Package: python-imaging (Red Hat Enterprise Linux 5) - Not affected
Package: python-imaging (Red Hat Enterprise Linux 6) - Not affected
Package: python-pillow (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-0740: pillow - Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c ...
vendor_debian·2016·CVSS 6.5
CVE-2016-0740 [MEDIUM] CVE-2016-0740: pillow - Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c ...
Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.
Scope: local
bookworm: resolved (fixed in 3.1.1-1)
bullseye: resolved (fixed in 3.1.1-1)
forky: resolved (fixed in 3.1.1-1)
sid: resolved (fixed in 3.1.1-1)
trixie: resolved (fixed in 3.1.1-1)
No detection rules found.
No public exploits indexed.
http://www.debian.org/security/2016/dsa-3499https://github.com/python-pillow/Pillow/blob/c3cb690fed5d4bf0c45576759de55d054916c165/CHANGES.rsthttps://github.com/python-pillow/Pillow/commit/6dcbf5bd96b717c58d7b642949da8d323099928ehttps://security.gentoo.org/glsa/201612-52http://www.debian.org/security/2016/dsa-3499https://github.com/python-pillow/Pillow/blob/c3cb690fed5d4bf0c45576759de55d054916c165/CHANGES.rsthttps://github.com/python-pillow/Pillow/commit/6dcbf5bd96b717c58d7b642949da8d323099928ehttps://security.gentoo.org/glsa/201612-52
2016-04-13
Published