CVE

Id
96010  
CVE No.
CVE-2016-9190  
Status
Candidate  
Description
Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.  
Phase
Assigned (20161104)  
Votes
None (candidate not yet proposed)  
Comments