yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-28219
Component Overview
Vulnerability Overview
Name
CVE-2024-28219
Source
NVD (
link
)
Debian (
link
)
Description
In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.
CWEs
CWE-680
Published Date
Apr 3, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://lists.debian.org/debian-lts-announce/2024/04/msg00008.html
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4XLPUT3VK4GQ6EVY525TT2QNUIXNRU5M/
Broken Link
https://pillow.readthedocs.io/en/stable/releasenotes/10.3.0.html#security
Release Notes
https://lists.debian.org/debian-lts-announce/2024/04/msg00008.html
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4XLPUT3VK4GQ6EVY525TT2QNUIXNRU5M/
Broken Link
https://pillow.readthedocs.io/en/stable/releasenotes/10.3.0.html#security
Release Notes
Analysis
#
Affected Component
Analysis
python3-pillow
Patched
Vulnerability Ratings
#
6.7
CVSSv31
5.9
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
python-pillow
buildroot
2025.02.x
11.1.0
Not Affected
python-pillow
buildroot
master
12.0.0
Not Affected
pillow
openwrt
master
12.2.0-r1
Not Affected
pillow
openwrt
openwrt-25.12
12.1.1-r1
Not Affected
python3-pillow
yocto
master
12.2.0
Not Affected
python3-pillow
yocto
scarthgap
10.3.0
Not Affected
Resolved with patches
#
python3-pillow (yocto:kirkstone)
#
Title
Author
Resolve
1
Use strncpy to avoid buffer overflow
Andrew Murray <radarhere@users.noreply.github.com>
CVE-2024-28219