Vulnerability Name:

CVE-2016-9189 (CCN-119017)

Assigned:2016-11-04
Published:2016-11-04
Updated:2017-07-01
Summary:Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-190
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2016-9189

Source: CONFIRM
Type: Vendor Advisory
http://pillow.readthedocs.io/en/3.4.x/releasenotes/3.3.2.html

Source: DEBIAN
Type: Third Party Advisory
DSA-3710

Source: BID
Type: Third Party Advisory, VDB Entry
94234

Source: CCN
Type: BID-94234
Python Pillow Multiple Security Vulnerabilities

Source: XF
Type: UNKNOWN
pillow-cve20169189-info-disc(119017)

Source: CCN
Type: Pillow GIT Repository
Multiple memory corruption vulnerabilities #2105

Source: CONFIRM
Type: Issue Tracking, Patch, Third Party Advisory
https://github.com/python-pillow/Pillow/issues/2105

Source: CONFIRM
Type: Issue Tracking, Patch, Third Party Advisory
https://github.com/python-pillow/Pillow/pull/2146/commits/c50ebe6459a131a1ea8ca531f10da616d3ceaa0f

Source: GENTOO
Type: UNKNOWN
GLSA-201612-52

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2016-9189

Vulnerable Configuration:Configuration 1:
  • cpe:/a:python:pillow:*:*:*:*:*:*:*:* (Version <= 3.3.1)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:python:pillow:3.3.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20169189
    V
    CVE-2016-9189
    2022-05-20
    oval:org.opensuse.security:def:58056
    P
    Security update for the Linux Kernel (Important)
    2021-12-06
    oval:org.opensuse.security:def:58025
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP3) (Important)
    2021-10-18
    oval:org.opensuse.security:def:57987
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:57913
    P
    Security update for avahi (Important)
    2021-06-03
    oval:org.opensuse.security:def:56983
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
    2021-04-28
    oval:org.opensuse.security:def:57428
    P
    Security update for xorg-x11-server (Important)
    2021-04-14
    oval:org.opensuse.security:def:58106
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:57156
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP3) (Important)
    2021-02-10
    oval:org.opensuse.security:def:58130
    P
    Security update for python-Pillow (Important)
    2020-12-01
    oval:org.opensuse.security:def:57713
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56583
    P
    Security update for gdm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57821
    P
    liblzo2-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56605
    P
    Security update for ghostscript (Important)
    2020-12-01
    oval:org.opensuse.security:def:57262
    P
    Security update for strongswan
    2020-12-01
    oval:org.opensuse.security:def:56745
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:56582
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:80765
    P
    Security update for python-Pillow (Important)
    2019-07-08
    oval:org.cisecurity:def:1437
    P
    DSA-3710-1 -- pillow -- security update
    2016-12-23
    oval:com.ubuntu.precise:def:20169189000
    V
    CVE-2016-9189 on Ubuntu 12.04 LTS (precise) - medium.
    2016-11-04
    oval:com.ubuntu.xenial:def:201691890000000
    V
    CVE-2016-9189 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-11-04
    oval:com.ubuntu.trusty:def:20169189000
    V
    CVE-2016-9189 on Ubuntu 14.04 LTS (trusty) - medium.
    2016-11-04
    oval:com.ubuntu.xenial:def:20169189000
    V
    CVE-2016-9189 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-11-04
    BACK
    python pillow *
    debian debian linux 8.0
    python pillow 3.3.1