Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-28219

Опубликовано: 03 апр. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.7

Описание

In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.

РелизСтатусПримечание
devel

not-affected

10.4.0-1
esm-infra-legacy/trusty

not-affected

2.3.0-1ubuntu3.4+esm4
esm-infra/bionic

released

5.1.0-1ubuntu0.8+esm1
esm-infra/focal

not-affected

7.0.0-4ubuntu0.9
esm-infra/xenial

released

3.1.2-0ubuntu1.6+esm2
focal

released

7.0.0-4ubuntu0.9
jammy

released

9.0.1-1ubuntu0.3
mantic

released

10.0.0-1ubuntu0.2
noble

released

10.2.0-1ubuntu1
oracular

not-affected

10.4.0-1

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

released

6.2.1-3ubuntu0.1~esm2
focal

ignored

end of standard support, was needed
jammy

DNE

mantic

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 28%
0.00095
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
около 1 года назад

In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.

CVSS3: 6.7
nvd
около 1 года назад

In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.

CVSS3: 6.7
debian
около 1 года назад

In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists bec ...

suse-cvrf
около 1 года назад

Security update for python-Pillow

suse-cvrf
около 1 года назад

Security update for python-Pillow

EPSS

Процентиль: 28%
0.00095
Низкий

6.7 Medium

CVSS3