Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Fedora 39: FEDORA-2024-e4b1b4eab1 Critical: Python Pillow Buffer Overflow

fedora
Calendar Grey April 10, 2024
Dist Fedora Esm H88
The recent upgrade of the Python Pillow library to version 10.3.0 addresses critical buffer overflow vulnerabilities in Fedora 39. Protect your environments now.
Update to 10.3.0.

Summary

Python image processing library, fork of the Python Imaging Library (PIL)

This library provides extensive file format support, an efficient

internal representation, and powerful image processing capabilities.

There are four subpackages: tk (tk interface), qt (PIL image wrapper for Qt),

devel (development) and doc (documentation).

Update Information:

Update to 10.3.0.

Change Log

* Tue Apr 2 2024 Sandro Mani - 10.3.0-1 - Update to 10.3.0 * Fri Jan 26 2024 Fedora Release Engineering - 10.2.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Mon Jan 22 2024 Fedora Release Engineering - 10.2.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

References


[ 1 ] Bug #2272567 - TRIAGE CVE-2024-28219 python-pillow: buffer overflow in _imagingcms.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2272567

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-e4b1b4eab1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-pillow
Product: Fedora 39
Version: 10.3.0
Release: 1.fc39
URL:
Summary: Python image processing library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here