VDB
KO
MEDIUM 6.7

GHSA-44wm-f244-xhp3

Pillow buffer overflow vulnerability

Details

In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / pillow
Introduced in: 0 Fixed in: 10.3.0
Fix pip install --upgrade 'pillow>=10.3.0'

References