Package "pillow"
Name: |
pillow
|
Description: |
This package is just an umbrella for a group of other packages,
it has no description. Description samples from packages in group:
- Examples for the Python Imaging Library
- Python Imaging Library (Python3)
- Python Imaging Library (Python3 debug extension)
- Python Imaging Library - ImageTk Module (Python3)
|
Latest version: |
7.2.0-1ubuntu0.1 |
Release: |
groovy (20.10) |
Level: |
security |
Repository: |
main |
Links
Other versions of "pillow" in Groovy
Packages in group
Deleted packages are displayed in grey.
Changelog
pillow (7.2.0-1ubuntu0.1) groovy-security; urgency=medium
* SECURITY UPDATE: buffer over-read via PCX file
- debian/patches/CVE-2020-35653.patch: don't trust the image to specify
a buffer size in src/PIL/PcxImagePlugin.py.
- CVE-2020-35653
* SECURITY UPDATE: heap overflow via YCbCr files
- debian/patches/CVE-2020-35654-1.patch: fix tiff comparison warnings
in src/libImaging/TiffDecode.c.
- debian/patches/CVE-2020-35654-2.patch: fix OOB write in
src/libImaging/TiffDecode.c.
- debian/patches/CVE-2020-35654-3.patch: rework ReadTile in
src/libImaging/TiffDecode.c.
- CVE-2020-35654
* SECURITY UPDATE: buffer over-read via SGI RLE image file
- debian/patches/CVE-2020-35655-1.patch: add checks to
src/libImaging/SgiRleDecode.c.
- debian/patches/CVE-2020-35655-2.patch: rework error flags in
src/libImaging/SgiRleDecode.c.
- CVE-2020-35655
-- Marc Deslauriers <email address hidden> Wed, 13 Jan 2021 09:35:02 -0500
|
CVE-2020-35653 |
In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffe |
CVE-2020-35654 |
In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts wit |
CVE-2020-35655 |
In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mi |
|
About
-
Send Feedback to @ubuntu_updates