MEDIUM 5.5 PyPI

Pillow Integer overflow in Map.c

GHSA-rwr3-c2q8-gm56 · CVE-2016-9189 · PYSEC-2016-8

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

Ready to move

Start Securing

Free, no credit card | First findings in minutes