Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow.
{
"nvd_published_at": null,
"severity": "CRITICAL",
"github_reviewed_at": "2020-06-16T21:41:06Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-119"
]
}