diff options
| author | Soumya Sambu <soumya.sambu@windriver.com> | 2025-11-07 17:04:28 +0530 |
|---|---|---|
| committer | Gyorgy Sarvari <skandigraun@gmail.com> | 2025-11-07 12:41:54 +0100 |
| commit | 7c7ab8ad4e2269d73fa6a572a7222aca3fdee27d (patch) | |
| tree | 3bd9d6b88361abf90ccb3d0a0ee1d669a6ccd609 /meta-python/recipes-devtools/python/python-matplotlib | |
| parent | b0d98aae8c41f43684b0d2afb7ee9a02ad4bd9c7 (diff) | |
| download | meta-openembedded-7c7ab8ad4e2269d73fa6a572a7222aca3fdee27d.tar.gz | |
python3-pillow: Fix CVE-2024-28219
In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because
strcpy is used instead of strncpy.
References:
https://nvd.nist.gov/vuln/detail/CVE-2024-28219
https://security-tracker.debian.org/tracker/CVE-2024-28219
Upstream patch:
https://github.com/python-pillow/Pillow/commit/2a93aba5cfcf6e241ab4f9392c13e3b74032c061
Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Diffstat (limited to 'meta-python/recipes-devtools/python/python-matplotlib')
0 files changed, 0 insertions, 0 deletions
