ALT-PU-2025-10639-3
Package python3-module-Pillow updated to version 10.3.0-alt0.c10.1 for branch c10f2 in task 392820.
Closed vulnerabilities
BDU:2024-00775
Уязвимость функции eval() модуля ImageMath библиотеки для работы с изображениями Pillow, позволяющая нарушителю выполнить произвольный код
BDU:2024-04737
Уязвимость файла _imagingcms.c библиотеки изображений Python Pillow, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2024-06540
Уязвимость функции truetype in ImageFont() библиотеки для работы с изображениями Pillow, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2023-44271
An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
- https://devhub.checkmarx.com/cve-details/CVE-2023-44271/
- https://github.com/python-pillow/Pillow/commit/1fe1bb49c452b0318cad12ea9d97c3bef188e9a7
- https://github.com/python-pillow/Pillow/pull/7244
- https://lists.debian.org/debian-lts-announce/2024/03/msg00021.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N2JOEDUJDQLCUII2LQYZYSM7RJL2I3P4/
- https://devhub.checkmarx.com/cve-details/CVE-2023-44271/
- https://github.com/python-pillow/Pillow/commit/1fe1bb49c452b0318cad12ea9d97c3bef188e9a7
- https://github.com/python-pillow/Pillow/pull/7244
- https://lists.debian.org/debian-lts-announce/2024/03/msg00021.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N2JOEDUJDQLCUII2LQYZYSM7RJL2I3P4/
Modified: 2024-11-21
CVE-2023-50447
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
- http://www.openwall.com/lists/oss-security/2024/01/20/1
- https://devhub.checkmarx.com/cve-details/CVE-2023-50447/
- https://duartecsantos.github.io/2024-01-02-CVE-2023-50447/
- https://github.com/python-pillow/Pillow/releases
- https://lists.debian.org/debian-lts-announce/2024/01/msg00019.html
- http://www.openwall.com/lists/oss-security/2024/01/20/1
- https://devhub.checkmarx.com/cve-details/CVE-2023-50447/
- https://duartecsantos.github.io/2024-01-02-CVE-2023-50447/
- https://github.com/python-pillow/Pillow/releases
- https://lists.debian.org/debian-lts-announce/2024/01/msg00019.html
Modified: 2024-11-21
CVE-2024-28219
In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.
- https://lists.debian.org/debian-lts-announce/2024/04/msg00008.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4XLPUT3VK4GQ6EVY525TT2QNUIXNRU5M/
- https://pillow.readthedocs.io/en/stable/releasenotes/10.3.0.html#security
- https://lists.debian.org/debian-lts-announce/2024/04/msg00008.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4XLPUT3VK4GQ6EVY525TT2QNUIXNRU5M/
- https://pillow.readthedocs.io/en/stable/releasenotes/10.3.0.html#security