Buffer overflow in Pillow - CVE-2024-28219
Published: April 3, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in "_imagingcms.c". A remote user can trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
EcoStruxure Power Operation
Gentoo Linux
Oracle Linux
Debian Linux
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Desktop 15
SUSE OpenStack Cloud
Anolis OS
SUSE OpenStack Cloud Crowbar
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
HPE Helion Openstack
Ubuntu
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Python 3 Module
openSUSE Leap
openEuler
Fedora
Nautobot
Oracle Financial Services Compliance Studio
Oracle Banking Corporate Lending Process Management
Oracle Banking Origination
Oracle Banking Liquidity Management
PowerVC
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Operations Monitor
Maximo Application Suite - Edge Data Collector
Oracle Communications Policy Management
Cloud Pak for Network Automation
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Policy
python3x-sqlparse (Red Hat package)
python-sqlparse (Red Hat package)
python3x-pulp-ansible (Red Hat package)
python-pulp-ansible (Red Hat package)
automation-eda-controller (Red Hat package)
ansible-rulebook (Red Hat package)
receptor (Red Hat package)
python3x-pydantic (Red Hat package)
python-pydantic (Red Hat package)
ansible-automation-platform-installer (Red Hat package)
ansible-core (Red Hat package)
python3x-requests (Red Hat package)
python-requests (Red Hat package)
python3x-jinja2 (Red Hat package)
python-jinja2 (Red Hat package)
python3x-idna (Red Hat package)
python-idna (Red Hat package)
python3x-aiohttp (Red Hat package)
python-aiohttp (Red Hat package)
python3x-pulpcore (Red Hat package)
python-pulpcore (Red Hat package)
python-Pillow-debugsource
python-Pillow-debuginfo
python-Pillow
automation-controller (Red Hat package)
automation-hub (Red Hat package)
python3x-galaxy-ng (Red Hat package)
python-galaxy-ng (Red Hat package)
python3-pillow-doc
python3-pillow-tk
python3-pillow-devel
python3-pillow
python-pillow (Red Hat package)
python3x-social-auth-app-django (Red Hat package)
python-social-auth-app-django (Red Hat package)
python3-Pillow
python3-Pillow-tk
python3-Pillow-debuginfo
python3-Pillow-tk-debuginfo
pillow (Debian package)
python3-pillow-help
python-pillow
python3-pillow-qt
python-pillow-debuginfo
python-pillow-debugsource
python311-Pillow-tk
python311-Pillow-debuginfo
python311-Pillow-tk-debuginfo
python311-Pillow
python3-pil (Ubuntu package)
dev-python/pillow
python3x-pillow (Red Hat package)
venv-openstack-horizon-x86_64
venv-openstack-horizon-hpe-x86_64
python3x-gunicorn (Red Hat package)
python-gunicorn (Red Hat package)
python3x-black (Red Hat package)
python-black (Red Hat package)
python3x-pyOpenSSL (Red Hat package)
python-pyOpenSSL (Red Hat package)
python3x-cryptography (Red Hat package)
python-cryptography (Red Hat package)
How to mitigate CVE-2024-28219
EcoStruxure Power Operation - update to 2024 CU2
Nautobot - update to 2.2.1
Maximo Application Suite - Edge Data Collector - update to 8.11.16
python3x-sqlparse (Red Hat package) - update to 0.5.0-1.el8ap
python-sqlparse (Red Hat package) - update to 0.5.0-1.el9ap
python3x-pulp-ansible (Red Hat package) - update to 0.20.7-1.el8ap
python-pulp-ansible (Red Hat package) - update to 0.20.7-1.el9ap
automation-eda-controller (Red Hat package) - addressed in versions 1.0.7-1.el8ap, 1.0.7-1.el9ap
ansible-rulebook (Red Hat package) - addressed in versions 1.0.7-1.el8ap, 1.0.7-1.el9ap
receptor (Red Hat package) - addressed in versions 1.4.8-1.el8ap, 1.4.8-1.el9ap
python3x-pydantic (Red Hat package) - update to 1.10.15-1.el8ap
python-pydantic (Red Hat package) - update to 1.10.15-1.el9ap
ansible-automation-platform-installer (Red Hat package) - addressed in versions 2.4-7.1.el8ap, 2.4-7.1.el9ap
Cloud Pak for Network Automation - update to 2.7.5
ansible-core (Red Hat package) - addressed in versions 2.15.11-1.el8ap, 2.15.11-1.el9ap
python3x-requests (Red Hat package) - update to 2.32.2-1.el8ap
python-requests (Red Hat package) - update to 2.32.2-1.el9ap
python3x-jinja2 (Red Hat package) - update to 3.1.4-1.el8ap
python-jinja2 (Red Hat package) - update to 3.1.4-1.el9ap
python3x-idna (Red Hat package) - update to 3.7-1.el8ap
python-idna (Red Hat package) - update to 3.7-1.el9ap
python3x-aiohttp (Red Hat package) - update to 3.9.5-1.el8ap
python-aiohttp (Red Hat package) - update to 3.9.5-1.el9ap
python3x-pulpcore (Red Hat package) - update to 3.28.27-1.el8ap
python-pulpcore (Red Hat package) - update to 3.28.27-1.el9ap
python-Pillow-debugsource - addressed in versions 4.2.1-3.29.2, 5.2.0-3.26.2, 7.2.0-150300.3.9.1, 9.5.0-150400.5.15.1
python-Pillow-debuginfo - addressed in versions 4.2.1-3.29.2, 5.2.0-3.26.2, 7.2.0-150300.3.9.1, 9.5.0-150400.5.15.1
python-Pillow - addressed in versions 4.2.1-3.29.2, 5.2.0-3.26.2
automation-controller (Red Hat package) - addressed in versions 4.5.7-1.el8ap, 4.5.7-1.el9ap
automation-hub (Red Hat package) - addressed in versions 4.9.2-1.el8ap, 4.9.2-1.el9ap
python3x-galaxy-ng (Red Hat package) - update to 4.9.2-1.el8ap
python-galaxy-ng (Red Hat package) - update to 4.9.2-1.el9ap
python3-pillow-doc - addressed in versions 5.1.1-21, 10.3.0-1
python3-pillow-tk - addressed in versions 5.1.1-21, 10.3.0-1
python3-pillow-devel - addressed in versions 5.1.1-21, 10.3.0-1
python3-pillow - addressed in versions 5.1.1-21, 10.3.0-1
python-pillow (Red Hat package) - addressed in versions 5.1.1-21.el8_10, 10.3.0-1.el9ap
python3x-social-auth-app-django (Red Hat package) - update to 5.4.1-1.el8ap
python-social-auth-app-django (Red Hat package) - update to 5.4.1-1.el9ap
python3-Pillow - update to 7.2.0-150300.3.9.1
python3-Pillow-tk - update to 7.2.0-150300.3.9.1
python3-Pillow-debuginfo - update to 7.2.0-150300.3.9.1
python3-Pillow-tk-debuginfo - update to 7.2.0-150300.3.9.1
pillow (Debian package) - addressed in versions 8.1.2+dfsg-0.3+deb11u2, 9.4.0-1.1+deb12u1
python3-pillow-help - update to 9.0.1-7
python-pillow - update to 9.0.1-7
python3-pillow - update to 9.0.1-7
python3-pillow-qt - update to 9.0.1-7
python3-pillow-tk - update to 9.0.1-7
python-pillow-debuginfo - update to 9.0.1-7
python-pillow-debugsource - update to 9.0.1-7
python3-pillow-devel - update to 9.0.1-7
python311-Pillow-tk - update to 9.5.0-150400.5.15.1
python311-Pillow-debuginfo - update to 9.5.0-150400.5.15.1
python311-Pillow-tk-debuginfo - update to 9.5.0-150400.5.15.1
python311-Pillow - update to 9.5.0-150400.5.15.1
python3-pil (Ubuntu package) - update to 10.2.0-1ubuntu1
dev-python/pillow - update to 10.3.0
python3-pillow-qt - update to 10.3.0-1
python3x-pillow (Red Hat package) - update to 10.3.0-1.el8ap
python-pillow - update to 10.3.0-1.fc39
venv-openstack-horizon-x86_64 - addressed in versions 12.0.5~dev6-14.58.2, 14.1.1~dev11-4.55.2
venv-openstack-horizon-hpe-x86_64 - update to 12.0.5~dev6-14.58.2
python3x-gunicorn (Red Hat package) - update to 22.0.0-1.el8ap
python-gunicorn (Red Hat package) - update to 22.0.0-1.el9ap
python3x-black (Red Hat package) - update to 22.8.0-2.el8ap
python-black (Red Hat package) - update to 22.8.0-2.el9ap
python3x-pyOpenSSL (Red Hat package) - update to 24.1.0-1.el8ap
python-pyOpenSSL (Red Hat package) - update to 24.1.0-1.el9ap
python3x-cryptography (Red Hat package) - update to 42.0.5-1.el8ap
python-cryptography (Red Hat package) - update to 42.0.5-1.el9ap
External References
Related Security Bulletins
- Remote code execution in Pillow
- Fedora 39 update for python-pillow
- SUSE update for python-Pillow
- openEuler update for python-pillow
- SUSE update for python-Pillow
- SUSE update for python-Pillow
- SUSE update for python-Pillow
- Multiple vulnerabilities in Nautobot
- Ubuntu update for pillow
- Ubuntu update for pillow-python2
- Ubuntu update for pillow
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Red Hat Enterprise Linux 8 update for python-pillow
- Debian update for pillow
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Gentoo update for Pillow
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Communications Operations Monitor
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in Oracle Financial Services Compliance Studio
- Multiple vulnerabilities in Oracle Banking Liquidity Management
- IBM Edge Data Collector update for Pillow
- Anolis OS update for python-pillow
- Anolis OS update for python-pillow
- Multiple vulnerabilities in Oracle Banking Origination
- Multiple vulnerabilities in Oracle Banking Corporate Lending Process Management
- Multiple vulnerabilities in Oracle Communications Policy Management
- Multiple vulnerabilities in Schneider Electric EcoStruxure Power Operation
- IBM PowerVC update for Pillow