Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow. External references: https://github.com/python-pillow/Pillow/pull/1714 Upstream fix: https://github.com/python-pillow/Pillow/commit/4e0d9b0b9740d258ade40cce248c93777362ac1e
Created python-pillow tracking bugs for this issue: Affects: fedora-all [bug 1327136]