CVE-2024-28219: Buffer Overflow
Published Apr 1, 2024
·Updated
In imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.
Affected Software
5 affected componentsFixes available
debian/pillow
8.1.2+dfsg-0.3+deb11u29.4.0-1.1+deb12u110.4.0-1
pip/pillow<10.3.0
10.3.0
redhat/pillow<10.3.0
10.3.0
Python Pillow<10.3.0
Debian Debian Linux=10.0
Remediation
Event History
Apr 1, 2024
Data Sourced
via Red Hat·11:34 PM
DescriptionSeverityAffected Software
Apr 3, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
Affected Software
Advisory Published
via GitHub·03:30 AM
May 4, 2024
Data Sourced
via Launchpad·03:31 PM
Description
Sep 17, 2024
Data Sourced
via Ubuntu·03:48 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-28219?
CVE-2024-28219 is classified as a high-severity vulnerability due to the potential for buffer overflow exploitation.
2
How do I fix CVE-2024-28219?
To fix CVE-2024-28219, upgrade to Pillow version 10.3.0 or later for all affected platforms.
3
Which versions of Pillow are affected by CVE-2024-28219?
Pillow versions prior to 10.3.0 are affected by CVE-2024-28219.
4
What is the exploit mechanism for CVE-2024-28219?
CVE-2024-28219 exploits a buffer overflow resulting from the improper use of strcpy instead of strncpy.
5
Is CVE-2024-28219 present in Debian packages?
Yes, CVE-2024-28219 affects several Debian packages, and users should upgrade to the specified remedial versions.