1+ {
2+ "aliases" : [
3+ " CVE-2016-4009" ,
4+ " GHSA-hvr8-466p-75rh"
5+ ],
6+ "summary" : " Pillow Integer overflow in ImagingResampleHorizontal\n Integer overflow in the `ImagingResampleHorizontal` function in `libImaging/Resample.c` in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow." ,
7+ "affected_packages" : [
8+ {
9+ "package" : {
10+ "type" : " pypi" ,
11+ "namespace" : " " ,
12+ "name" : " pillow" ,
13+ "version" : " " ,
14+ "qualifiers" : " " ,
15+ "subpath" : " "
16+ },
17+ "affected_version_range" : null ,
18+ "fixed_version" : " 3.1.1"
19+ }
20+ ],
21+ "references" : [
22+ {
23+ "reference_id" : " " ,
24+ "reference_type" : " " ,
25+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2016-4009" ,
26+ "severities" : [
27+ {
28+ "system" : " cvssv3.1" ,
29+ "value" : " 9.8" ,
30+ "scoring_elements" : " CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
31+ },
32+ {
33+ "system" : " cvssv4" ,
34+ "value" : " 9.3" ,
35+ "scoring_elements" : " CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
36+ },
37+ {
38+ "system" : " generic_textual" ,
39+ "value" : " CRITICAL" ,
40+ "scoring_elements" : " "
41+ }
42+ ]
43+ },
44+ {
45+ "reference_id" : " " ,
46+ "reference_type" : " " ,
47+ "url" : " https://github.com/python-pillow/Pillow/pull/1714" ,
48+ "severities" : [
49+ {
50+ "system" : " cvssv3.1" ,
51+ "value" : " 9.8" ,
52+ "scoring_elements" : " CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
53+ },
54+ {
55+ "system" : " cvssv4" ,
56+ "value" : " 9.3" ,
57+ "scoring_elements" : " CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
58+ },
59+ {
60+ "system" : " generic_textual" ,
61+ "value" : " CRITICAL" ,
62+ "scoring_elements" : " "
63+ }
64+ ]
65+ },
66+ {
67+ "reference_id" : " " ,
68+ "reference_type" : " " ,
69+ "url" : " https://github.com/python-pillow/Pillow/commit/4e0d9b0b9740d258ade40cce248c93777362ac1e" ,
70+ "severities" : [
71+ {
72+ "system" : " cvssv3.1" ,
73+ "value" : " 9.8" ,
74+ "scoring_elements" : " CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
75+ },
76+ {
77+ "system" : " cvssv4" ,
78+ "value" : " 9.3" ,
79+ "scoring_elements" : " CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
80+ },
81+ {
82+ "system" : " generic_textual" ,
83+ "value" : " CRITICAL" ,
84+ "scoring_elements" : " "
85+ }
86+ ]
87+ },
88+ {
89+ "reference_id" : " " ,
90+ "reference_type" : " " ,
91+ "url" : " https://github.com/advisories/GHSA-hvr8-466p-75rh" ,
92+ "severities" : [
93+ {
94+ "system" : " cvssv3.1" ,
95+ "value" : " 9.8" ,
96+ "scoring_elements" : " CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
97+ },
98+ {
99+ "system" : " cvssv4" ,
100+ "value" : " 9.3" ,
101+ "scoring_elements" : " CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
102+ },
103+ {
104+ "system" : " generic_textual" ,
105+ "value" : " CRITICAL" ,
106+ "scoring_elements" : " "
107+ }
108+ ]
109+ },
110+ {
111+ "reference_id" : " " ,
112+ "reference_type" : " " ,
113+ "url" : " https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2016-7.yaml" ,
114+ "severities" : [
115+ {
116+ "system" : " cvssv3.1" ,
117+ "value" : " 9.8" ,
118+ "scoring_elements" : " CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
119+ },
120+ {
121+ "system" : " cvssv4" ,
122+ "value" : " 9.3" ,
123+ "scoring_elements" : " CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
124+ },
125+ {
126+ "system" : " generic_textual" ,
127+ "value" : " CRITICAL" ,
128+ "scoring_elements" : " "
129+ }
130+ ]
131+ },
132+ {
133+ "reference_id" : " " ,
134+ "reference_type" : " " ,
135+ "url" : " https://github.com/python-pillow/Pillow" ,
136+ "severities" : [
137+ {
138+ "system" : " cvssv3.1" ,
139+ "value" : " 9.8" ,
140+ "scoring_elements" : " CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
141+ },
142+ {
143+ "system" : " cvssv4" ,
144+ "value" : " 9.3" ,
145+ "scoring_elements" : " CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
146+ },
147+ {
148+ "system" : " generic_textual" ,
149+ "value" : " CRITICAL" ,
150+ "scoring_elements" : " "
151+ }
152+ ]
153+ },
154+ {
155+ "reference_id" : " " ,
156+ "reference_type" : " " ,
157+ "url" : " https://github.com/python-pillow/Pillow/blob/c3cb690fed5d4bf0c45576759de55d054916c165/CHANGES.rst" ,
158+ "severities" : [
159+ {
160+ "system" : " cvssv3.1" ,
161+ "value" : " 9.8" ,
162+ "scoring_elements" : " CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
163+ },
164+ {
165+ "system" : " cvssv4" ,
166+ "value" : " 9.3" ,
167+ "scoring_elements" : " CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
168+ },
169+ {
170+ "system" : " generic_textual" ,
171+ "value" : " CRITICAL" ,
172+ "scoring_elements" : " "
173+ }
174+ ]
175+ },
176+ {
177+ "reference_id" : " " ,
178+ "reference_type" : " " ,
179+ "url" : " https://security.gentoo.org/glsa/201612-52" ,
180+ "severities" : [
181+ {
182+ "system" : " cvssv3.1" ,
183+ "value" : " 9.8" ,
184+ "scoring_elements" : " CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
185+ },
186+ {
187+ "system" : " cvssv4" ,
188+ "value" : " 9.3" ,
189+ "scoring_elements" : " CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
190+ },
191+ {
192+ "system" : " generic_textual" ,
193+ "value" : " CRITICAL" ,
194+ "scoring_elements" : " "
195+ }
196+ ]
197+ },
198+ {
199+ "reference_id" : " " ,
200+ "reference_type" : " " ,
201+ "url" : " http://www.securityfocus.com/bid/86064" ,
202+ "severities" : [
203+ {
204+ "system" : " cvssv3.1" ,
205+ "value" : " 9.8" ,
206+ "scoring_elements" : " CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
207+ },
208+ {
209+ "system" : " cvssv4" ,
210+ "value" : " 9.3" ,
211+ "scoring_elements" : " CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
212+ },
213+ {
214+ "system" : " generic_textual" ,
215+ "value" : " CRITICAL" ,
216+ "scoring_elements" : " "
217+ }
218+ ]
219+ }
220+ ],
221+ "date_published" : " 2018-07-24T20:15:48+00:00" ,
222+ "weaknesses" : [
223+ 119
224+ ],
225+ "url" : " https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/github_osv_test_8.json"
226+ }
0 commit comments