cbcvebase.
CVE-2024-28219
published 2024-04-03

CVE-2024-28219: In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.

PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.99%
58.6th percentile
In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianpillow< pillow 9.4.0-1.1+deb12u1 (bookworm)pillow 9.4.0-1.1+deb12u1 (bookworm)
pythonpillow< 10.3.010.3.0
pythonpillow>= 0 < 8.1.2+dfsg-0.3+deb11u28.1.2+dfsg-0.3+deb11u2
pythonpillow>= 0 < 9.4.0-1.1+deb12u19.4.0-1.1+deb12u1
pythonpillow>= 0 < 10.3.0-110.3.0-1
pythonpillow>= 0 < 10.3.0-110.3.0-1
pythonpillow>= 0 < 10.3.010.3.0

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_debian6.7MEDIUM
vendor_oracle6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.