CVE-2016-9190
Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" appro
Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.
HIGH · CVSS 7.8
EPSS 0.00566
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0