{"id":"CVE-2016-4009","details":"Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow.","aliases":["GHSA-hvr8-466p-75rh","PYSEC-2016-7"],"modified":"2026-05-17T11:55:15.447796287Z","published":"2016-04-13T16:59:25.353Z","related":["SUSE-SU-2019:2334-1","SUSE-SU-2020:1194-1"],"database_specific":{},"references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/86064"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201612-52"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/blob/c3cb690fed5d4bf0c45576759de55d054916c165/CHANGES.rst"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/4e0d9b0b9740d258ade40cce248c93777362ac1e"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/1714"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}