Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.
"https://github.com/pypa/advisory-database/blob/main/vulns/pillow/PYSEC-2016-8.yaml"