April 29, 2024, 1:04 p.m. |

Ubuntu security notices ubuntu.com

USN-6744-1 fixed a vulnerability in Pillow. This update
provides the corresponding updates for Ubuntu 24.04 LTS.

Original advisory details:

Hugo van Kemenade discovered that Pillow was not properly performing
bounds checks when processing an ICC file, which could lead to a buffer
overflow. If a user or automated system were tricked into processing a
specially crafted ICC file, an attacker could possibly use this issue
to cause a denial of service or execute arbitrary code.

advisory automated buffer buffer overflow file icc lts overflow performing system ubuntu update updates usn van vulnerability

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Senior SecOps Security Architect

@ SGS | Madrid, Spain

Auditeur(trice) de configuration et d’architecture - Cybersécurité - Toulouse

@ Sopra Steria | Colomiers, France

Cybersecurity - staż SantanderTech

@ Santander | Wrocław