Package "pillow"

Name: pillow


This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Examples for the Python Imaging Library
  • Python Imaging Library (Python3)
  • Python Imaging Library (Python3 debug extension)
  • Python Imaging Library - ImageTk Module (Python3)

Latest version: 7.2.0-1ubuntu0.1
Release: groovy (20.10)
Level: updates
Repository: main


Other versions of "pillow" in Groovy

Repository Area Version
base main 7.2.0-1
security main 7.2.0-1ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Version: 7.2.0-1ubuntu0.1 2021-01-18 20:07:11 UTC

  pillow (7.2.0-1ubuntu0.1) groovy-security; urgency=medium

  * SECURITY UPDATE: buffer over-read via PCX file
    - debian/patches/CVE-2020-35653.patch: don't trust the image to specify
      a buffer size in src/PIL/PcxImagePlugin.py.
    - CVE-2020-35653
  * SECURITY UPDATE: heap overflow via YCbCr files
    - debian/patches/CVE-2020-35654-1.patch: fix tiff comparison warnings
      in src/libImaging/TiffDecode.c.
    - debian/patches/CVE-2020-35654-2.patch: fix OOB write in
    - debian/patches/CVE-2020-35654-3.patch: rework ReadTile in
    - CVE-2020-35654
  * SECURITY UPDATE: buffer over-read via SGI RLE image file
    - debian/patches/CVE-2020-35655-1.patch: add checks to
    - debian/patches/CVE-2020-35655-2.patch: rework error flags in
    - CVE-2020-35655

 -- Marc Deslauriers <email address hidden> Wed, 13 Jan 2021 09:35:02 -0500

CVE-2020-35653 In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffe
CVE-2020-35654 In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts wit
CVE-2020-35655 In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mi

About   -   Send Feedback to @ubuntu_updates