python-pillow-5.1.1-21.el8_10

エラータID: AXSA:2024-8509:05

Release date: 
Thursday, July 4, 2024 - 12:39
Subject: 
python-pillow-5.1.1-21.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

The python-pillow packages contain a Python image processing library that provides extensive file format support, an efficient internal representation, and powerful image-processing capabilities.

Security Fix(es):

* python-pillow: buffer overflow in _imagingcms.c (CVE-2024-28219)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-28219
In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. python-pillow-5.1.1-21.el8_10.src.rpm
    MD5: 9a38d054348f86e23a6f1c5e93bf01d2
    SHA-256: 654c2181310515f1fbdbe4cbbb997a00d15e387161df315b9d4276ab1d510d82
    Size: 13.52 MB

Asianux Server 8 for x86_64
  1. python3-pillow-5.1.1-21.el8_10.i686.rpm
    MD5: 91057fce6b05fb86df00642dadd7398e
    SHA-256: 8dd3a985c32488948ba3705f7dd7c0505db84645b5758626a40dc04c3b02b224
    Size: 640.32 kB
  2. python3-pillow-5.1.1-21.el8_10.x86_64.rpm
    MD5: 15e7b85caee890f8b904ab0f3ad51791
    SHA-256: 84df88e06d18482afeb4121fa3992135bdeb701f4109cc0611043bcd9019f78d
    Size: 631.71 kB
  3. python3-pillow-devel-5.1.1-21.el8_10.i686.rpm
    MD5: 54db92fe75d4a4c60dbe9dd61e494343
    SHA-256: e82fdcb3359ff20cb68a136253bfe034643138b540be69f35439121585f8fca8
    Size: 33.56 kB
  4. python3-pillow-devel-5.1.1-21.el8_10.x86_64.rpm
    MD5: f34dbb69c21996cf653e0d4b00eea7f4
    SHA-256: d2047247ea4674316b1f92814b887958252c13f9b29d95e715189803db92f5e6
    Size: 33.53 kB
  5. python3-pillow-doc-5.1.1-21.el8_10.noarch.rpm
    MD5: d33ea825abea8e1f7d82d4ee71c8cccf
    SHA-256: b692a65444526015d034e584afc5bb8f6c8db7483f53ea716bb1e0efecab5596
    Size: 1.99 MB
  6. python3-pillow-tk-5.1.1-21.el8_10.x86_64.rpm
    MD5: c4059d941776a6fd07c817d14756cbfd
    SHA-256: c632ea4ac6582cb4ecbfd7ad12c7f1465aea02c6da9f78f4a8e59ab88d709144
    Size: 36.68 kB