Hide Forgot
It was found that in storage.c, the image size is not checked for negative values. This can lead to a null pointer dereference in 3.3.x, or a dereference of junk memory prior to that. Upstream patch: https://github.com/python-pillow/Pillow/commit/5d8a0be45aad78c5a22c8d099118ee26ef8144af
Acknowledgments: Name: the Pillow project
Upstream bug: https://github.com/python-pillow/Pillow/issues/2105 References: http://pillow.readthedocs.io/en/3.4.x/releasenotes/3.3.2.html
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.