CVE-2016-0775
published 2016-04-13CVE-2016-0775: Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash)…
PriorityP427medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
2.69%
84.2th percentile
Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | pillow | < pillow 3.1.1-1 (bookworm) | pillow 3.1.1-1 (bookworm) |
| python | pillow | <= 3.1.0 | — |
| python | pillow | >= 0 < 3.1.1-1 | 3.1.1-1 |
| python | pillow | >= 0 < 3.1.1-1 | 3.1.1-1 |
| python | pillow | >= 0 < 3.1.1-1 | 3.1.1-1 |
| python | pillow | >= 0 < 3.1.1-1 | 3.1.1-1 |
| python | pillow | >= 0 < 3.1.1 | 3.1.1 |
| python | pillow | >= 0 < 2.3.0-1ubuntu3.3 | 2.3.0-1ubuntu3.3 |
| python | pillow | >= 0 < 2.3.0-1ubuntu3.2 | 2.3.0-1ubuntu3.2 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Pillow Buffer overflow in ImagingFliDecode
osv·2018-07-24
CVE-2016-0775 [HIGH] Pillow Buffer overflow in ImagingFliDecode
Pillow Buffer overflow in ImagingFliDecode
Buffer overflow in the `ImagingFliDecode` function in `libImaging/FliDecode.c` in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.
GHSA
Pillow Buffer overflow in ImagingFliDecode
ghsa·2018-07-24
CVE-2016-0775 [HIGH] CWE-119 Pillow Buffer overflow in ImagingFliDecode
Pillow Buffer overflow in ImagingFliDecode
Buffer overflow in the `ImagingFliDecode` function in `libImaging/FliDecode.c` in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.
OSV
Pillow regression
osv·2016-09-30·CVSS 5.0
CVE-2014-9601 [MEDIUM] Pillow regression
Pillow regression
USN-3090-1 fixed vulnerabilities in Pillow. The patch to fix CVE-2014-9601
caused a regression which resulted in failures when processing certain
png images. This update temporarily reverts the security fix for CVE-2014-9601
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorrectly handled certain malformed
FLI,
OSV
Pillow vulnerabilities
osv·2016-09-27·CVSS 5.0
CVE-2014-9601 [MEDIUM] Pillow vulnerabilities
Pillow vulnerabilities
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorrectly handled certain malformed
FLI, Tiff, and PhotoCD files. A remote attacker could use this issue to
cause Pillow to crash, resulting in a denial of service.
(CVE-2016-0740, CVE-2016-0775, CVE-2016-2533)
OSV
CVE-2016-0775: Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode
osv·2016-04-13·CVSS 6.5
CVE-2016-0775 [MEDIUM] CVE-2016-0775: Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode
Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.
Ubuntu
Pillow regresssion
vendor_ubuntu·2016-09-30·CVSS 5.0
CVE-2014-9601 [MEDIUM] Pillow regresssion
Title: Pillow regresssion
Summary: Pillow regresssion
USN-3090-1 fixed vulnerabilities in Pillow. The patch to fix CVE-2014-9601
caused a regression which resulted in failures when processing certain
png images. This update temporarily reverts the security fix for CVE-2014-9601
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorr
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2016-09-27·CVSS 5.0
CVE-2014-3589 [MEDIUM] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Pillow could be made to crash if it received specially crafted input or opened
a specially crafted file.
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorrectly handled certain malformed
FLI, Tiff, and PhotoCD files. A remote attacker could use this issue to
cause Pillow to crash, resulting in a denial of service.
(CVE-2016-0740, CVE-2016-0775, CVE-2016-2533)
Instructions: In general
Ubuntu
Python Imaging Library vulnerabilities
vendor_ubuntu·2016-09-15·CVSS 5.0
CVE-2014-3589 [MEDIUM] Python Imaging Library vulnerabilities
Title: Python Imaging Library vulnerabilities
Summary: Python Imaging Libary could be made to crash if it received specially crafted
input or opened a specially crafted file.
Eric Soroos discovered that the Python Imaging Library incorrectly handled
certain malformed FLI or PhotoCD files. A remote attacker could use this
issue to cause Python Imaging Library to crash, resulting in a denial of
service. (CVE-2016-0775, CVE-2016-2533)
Andrew Drake discovered that the Python Imaging Libray incorrectly validated
input. A remote attacker could use this to cause Python Imaging Library to
crash, resulting in a denial of service. (CVE-2014-3589)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-pillow: Buffer overflow in FliDecode.c
vendor_redhat·2016-02-04·CVSS 6.5
CVE-2016-0775 [MEDIUM] CWE-120 python-pillow: Buffer overflow in FliDecode.c
python-pillow: Buffer overflow in FliDecode.c
Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.
Package: python-imaging (Red Hat Enterprise Linux 5) - Will not fix
Package: python-imaging (Red Hat Enterprise Linux 6) - Will not fix
Package: python-pillow (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-0775: pillow - Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pi...
vendor_debian·2016·CVSS 6.5
CVE-2016-0775 [MEDIUM] CVE-2016-0775: pillow - Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pi...
Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.
Scope: local
bookworm: resolved (fixed in 3.1.1-1)
bullseye: resolved (fixed in 3.1.1-1)
forky: resolved (fixed in 3.1.1-1)
sid: resolved (fixed in 3.1.1-1)
trixie: resolved (fixed in 3.1.1-1)
No detection rules found.
No public exploits indexed.
arXiv
Common Vulnerability Scoring System Prediction based on Open Source Intelligence Information Sources
arxiv_fulltext·2022-10-05
Common Vulnerability Scoring System Prediction based on Open Source Intelligence Information Sources
plain
[ *cvss Prediction based on *osint Information Sources]
*cvss Prediction based on *osint Information Sources
## Abstract
The number of newly published vulnerabilities is constantly increasing.
Until now, the information available when a new vulnerability is published is manually assessed by experts using a *cvss vector and score.
This assessment is time consuming and requires expertise.
Various works already try to predict *cvss vectors or scores using machine learning based on the textual descriptions of the vulnerability to enable faster assessment.
However, for this purpose, previous works only use the texts available in databases such as *nvd.
With this work, the publicly available web pages referenced in the *nvd are analyzed and made available as sources of texts through web
Bugzilla
CVE-2016-0775 python-pillow: Buffer overflow in FliDecode.c
bugzilla·2016-01-25·CVSS 6.5
CVE-2016-0775 [MEDIUM] CVE-2016-0775 python-pillow: Buffer overflow in FliDecode.c
CVE-2016-0775 python-pillow: Buffer overflow in FliDecode.c
A buffer overflow vulnerability in FliDecode.c was reported, affecting all versions of python-pillow at least from 1.1.7 release.
Vulnerable code:
case 16:
/* COPY chunk */
for (y = 0; y ysize; y++) {
UINT8* buf = (UINT8*) im->image[y];
memcpy(buf+x, data, state->xsize);
data += state->xsize;
}
break;
x is used in several internal temporary variable roles, but can take a value up to the width of the image from different chunk sizes. im->image[y] is a set of row pointers to segments of memory that are the size of the row. At the max y, this will write the contents of the line off the end of the memory buffer. This writes into python object storage in a region where there are function pointers.
Reproducer and proposed fix can b
http://www.debian.org/security/2016/dsa-3499https://github.com/python-pillow/Pillow/blob/c3cb690fed5d4bf0c45576759de55d054916c165/CHANGES.rsthttps://github.com/python-pillow/Pillow/commit/893a40850c2d5da41537958e40569c029a6e127bhttps://security.gentoo.org/glsa/201612-52http://www.debian.org/security/2016/dsa-3499https://github.com/python-pillow/Pillow/blob/c3cb690fed5d4bf0c45576759de55d054916c165/CHANGES.rsthttps://github.com/python-pillow/Pillow/commit/893a40850c2d5da41537958e40569c029a6e127bhttps://security.gentoo.org/glsa/201612-52
2016-04-13
Published