Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19662 | Pillow vulnerability can cause write buffer overflow on BCn encoding |
Github GHSA |
GHSA-xg8h-j46f-w952 | Pillow vulnerability can cause write buffer overflow on BCn encoding |
Wed, 15 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Python
Python pillow |
|
| CPEs | cpe:2.3:a:python:pillow:11.2.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Python
Python pillow |
Fri, 04 Jul 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 01 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Jul 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checking for available space. This only affects users who save untrusted data as a compressed DDS image. This issue has been patched in version 11.3.0. | |
| Title | Pillow Vulnerable to Write Buffer Overflow on BCn encoding | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-01T19:42:22.348Z
Reserved: 2025-05-19T15:46:00.396Z
Link: CVE-2025-48379
Updated: 2025-07-01T19:42:11.950Z
Status : Analyzed
Published: 2025-07-01T19:15:27.353
Modified: 2025-10-15T20:03:42.337
Link: CVE-2025-48379
OpenCVE Enrichment
No data.
EUVD
Github GHSA