UbuntuUpdates.org

Package "pillow"

Name: pillow

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Examples for the Python Imaging Library
  • Python Imaging Library (Python3)
  • Python Imaging Library (Python3 debug extension)
  • Python Imaging Library - ImageTk Module (Python3)

Latest version: 7.2.0-1ubuntu0.1
Release: groovy (20.10)
Level: security
Repository: main

Links



Other versions of "pillow" in Groovy

Repository Area Version
base main 7.2.0-1
updates main 7.2.0-1ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 7.2.0-1ubuntu0.1 2021-01-18 19:06:32 UTC

  pillow (7.2.0-1ubuntu0.1) groovy-security; urgency=medium

  * SECURITY UPDATE: buffer over-read via PCX file
    - debian/patches/CVE-2020-35653.patch: don't trust the image to specify
      a buffer size in src/PIL/PcxImagePlugin.py.
    - CVE-2020-35653
  * SECURITY UPDATE: heap overflow via YCbCr files
    - debian/patches/CVE-2020-35654-1.patch: fix tiff comparison warnings
      in src/libImaging/TiffDecode.c.
    - debian/patches/CVE-2020-35654-2.patch: fix OOB write in
      src/libImaging/TiffDecode.c.
    - debian/patches/CVE-2020-35654-3.patch: rework ReadTile in
      src/libImaging/TiffDecode.c.
    - CVE-2020-35654
  * SECURITY UPDATE: buffer over-read via SGI RLE image file
    - debian/patches/CVE-2020-35655-1.patch: add checks to
      src/libImaging/SgiRleDecode.c.
    - debian/patches/CVE-2020-35655-2.patch: rework error flags in
      src/libImaging/SgiRleDecode.c.
    - CVE-2020-35655

 -- Marc Deslauriers <email address hidden> Wed, 13 Jan 2021 09:35:02 -0500

CVE-2020-35653 In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffe
CVE-2020-35654 In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts wit
CVE-2020-35655 In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mi



About   -   Send Feedback to @ubuntu_updates