pillow 7.2.0-1ubuntu0.1 source package in Ubuntu

Changelog

pillow (7.2.0-1ubuntu0.1) groovy-security; urgency=medium

  * SECURITY UPDATE: buffer over-read via PCX file
    - debian/patches/CVE-2020-35653.patch: don't trust the image to specify
      a buffer size in src/PIL/PcxImagePlugin.py.
    - CVE-2020-35653
  * SECURITY UPDATE: heap overflow via YCbCr files
    - debian/patches/CVE-2020-35654-1.patch: fix tiff comparison warnings
      in src/libImaging/TiffDecode.c.
    - debian/patches/CVE-2020-35654-2.patch: fix OOB write in
      src/libImaging/TiffDecode.c.
    - debian/patches/CVE-2020-35654-3.patch: rework ReadTile in
      src/libImaging/TiffDecode.c.
    - CVE-2020-35654
  * SECURITY UPDATE: buffer over-read via SGI RLE image file
    - debian/patches/CVE-2020-35655-1.patch: add checks to
      src/libImaging/SgiRleDecode.c.
    - debian/patches/CVE-2020-35655-2.patch: rework error flags in
      src/libImaging/SgiRleDecode.c.
    - CVE-2020-35655

 -- Marc Deslauriers <email address hidden>  Wed, 13 Jan 2021 09:35:02 -0500

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Groovy
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
python
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
pillow_7.2.0.orig.tar.xz 32.0 MiB 8ab9247b05129164d3f5f060d171242cb29c0f4e3da8a4b4ca9a64b85663fa5a
pillow_7.2.0-1ubuntu0.1.debian.tar.xz 21.2 KiB 551f31a886e705819a44ce3a4fca761bb5a607d100ccb0d1b0edb7b350ca3e2e
pillow_7.2.0-1ubuntu0.1.dsc 2.4 KiB ad080579a922fb7fb0a82d90a3a31df846255db2292fadd2b52588d75e123ddd

View changes file

Binary packages built by this source

python-pil-doc: No summary available for python-pil-doc in ubuntu groovy.

No description available for python-pil-doc in ubuntu groovy.

python3-pil: No summary available for python3-pil in ubuntu groovy.

No description available for python3-pil in ubuntu groovy.

python3-pil-dbg: No summary available for python3-pil-dbg in ubuntu groovy.

No description available for python3-pil-dbg in ubuntu groovy.

python3-pil.imagetk: No summary available for python3-pil.imagetk in ubuntu groovy.

No description available for python3-pil.imagetk in ubuntu groovy.

python3-pil.imagetk-dbg: No summary available for python3-pil.imagetk-dbg in ubuntu groovy.

No description available for python3-pil.imagetk-dbg in ubuntu groovy.