Описание
In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 10.4.0-1 |
| esm-infra-legacy/trusty | released | 2.3.0-1ubuntu3.4+esm4 |
| esm-infra/bionic | released | 5.1.0-1ubuntu0.8+esm1 |
| esm-infra/focal | released | 7.0.0-4ubuntu0.9 |
| esm-infra/xenial | released | 3.1.2-0ubuntu1.6+esm2 |
| focal | released | 7.0.0-4ubuntu0.9 |
| jammy | released | 9.0.1-1ubuntu0.3 |
| mantic | released | 10.0.0-1ubuntu0.2 |
| noble | released | 10.2.0-1ubuntu1 |
| oracular | not-affected | 10.4.0-1 |
Показывать по
10
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-apps/focal | released | 6.2.1-3ubuntu0.1~esm2 |
| focal | ignored | end of standard support, was needed |
| jammy | DNE | |
| mantic | DNE | |
| noble | DNE | |
| oracular | DNE | |
| plucky | DNE | |
| upstream | needs-triage |
Показывать по
10
EPSS
Процентиль: 51%
0.00284
Низкий
6.7 Medium
CVSS3
Связанные уязвимости
CVSS3: 6.5
redhat
больше 1 года назад
In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.
CVSS3: 6.7
nvd
больше 1 года назад
In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.
CVSS3: 6.7
debian
больше 1 года назад
In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists bec ...
EPSS
Процентиль: 51%
0.00284
Низкий
6.7 Medium
CVSS3