CVE-2016-2533

medium
Published 2018-07-24 · Modified 2026-04-09
CVSS v3
6.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS v2
4.3
VIR risk
6.5

Description

Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-2533

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/python-pillow/Pillow/blob/c3cb690fed5d4bf0c45576759de55d054916c165/CHANGES.rst

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2016-2533.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debian7.0affected
debian debian8.0affected
debian debianbookwormfixed3.1.1-1
debian debianbullseyefixed3.1.1-1
debian debianforkyfixed3.1.1-1
debian debiansidfixed3.1.1-1
debian debiantrixiefixed3.1.1-1

Package impact

EcosystemPackageVulnerableFixed
python PyPIpillow<3.1.13.1.1
python PyPIpillow<ae453aa18b66af54e7ff716f4ccb33adca60afd4||<3.1.15bdf54b5a76b54fb00bd05f2d733e0a4173eefc9

Application impact

VendorProductVersionsFixed
pythonpillow{"endIncluding":"3.1.0"}
python_imaging_projectpython_imaging{"endIncluding":"1.1.7"}

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.