Candidate: CVE-2016-3076 PublicDate: 2017-04-24 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3076 https://github.com/python-pillow/Pillow/commit/a1f244343df389cf15cdfff80327594821097295 (3.1.2) Description: Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file. Ubuntu-Description: Notes: mdeslaur> see if built against openjpeg sbeattie> not built against openjpeg sbeattie> j2k support added to pillow in 2.4.0 release Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_python-imaging: upstream_python-imaging: needs-triage precise_python-imaging: not-affected (no j2k support) trusty_python-imaging: DNE trusty/esm_python-imaging: DNE vivid/stable-phone-overlay_python-imaging: DNE vivid/ubuntu-core_python-imaging: DNE wily_python-imaging: DNE xenial_python-imaging: DNE devel_python-imaging: DNE Patches_pillow: upstream_pillow: needs-triage precise_pillow: DNE trusty_pillow: not-affected (no j2k support) trusty/esm_pillow: not-affected (no j2k support) vivid/stable-phone-overlay_pillow: DNE vivid/ubuntu-core_pillow: DNE wily_pillow: ignored (reached end-of-life) xenial_pillow: not-affected (3.1.2-0ubuntu1) esm-infra/xenial_pillow: not-affected (3.1.2-0ubuntu1) devel_pillow: not-affected (3.1.2-0ubuntu1)