pillow 8.1.2-1ubuntu0.2 source package in Ubuntu

Changelog

pillow (8.1.2-1ubuntu0.2) hirsute-security; urgency=medium

  * SECURITY UPDATE: regular expression DoS
    - debian/patches/CVE-2021-23437.patch: raise ValueError if color
      specifier is too long in Tests/test_imagecolor.py,
      src/PIL/ImageColor.py.
    - CVE-2021-23437
  * SECURITY UPDATE: Dos via buffer overflow
    - debian/patches/CVE-2021-34552.patch: limit sprintf modes to 10
      characters in src/libImaging/Convert.c.
    - CVE-2021-34552
  * SECURITY UPDATE: improper initialization
    - debian/patches/CVE-2022-22815.patch: initialize coordinates to zero
      in Tests/test_imagepath.py, src/path.c.
    - CVE-2022-22815
  * SECURITY UPDATE: buffer over-read during initialization
    - debian/patches/CVE-2022-22816.patch: handle case where path count is
      zero in Tests/test_imagepath.py, src/path.c.
    - CVE-2022-22816
  * SECURITY UPDATE: evaluation of arbitrary expressions
    - debian/patches/CVE-2022-22817.patch: restrict builtins for
      ImageMath.eval in Tests/test_imagemath.py, src/PIL/ImageMath.py.
    - CVE-2022-22817

 -- Marc Deslauriers <email address hidden>  Wed, 12 Jan 2022 12:54:47 -0500

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Hirsute
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
python
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
pillow_8.1.2.orig.tar.xz 37.5 MiB f0c6476d4cbea59610df8c35218f8caac3ee3f5774bd732dfcdcfb5af67f855b
pillow_8.1.2-1ubuntu0.2.debian.tar.xz 22.9 KiB 90c60a733587150f43a3b3eecbb8b28c8dcb483610946ea2235c7b2f0a0c6dfa
pillow_8.1.2-1ubuntu0.2.dsc 2.5 KiB 9f7b1692a91c1d0f5f7a44d6b1b1b96edfcc1f1a1821a7b7a51b7290b733ffe6

View changes file

Binary packages built by this source

python-pil-doc: No summary available for python-pil-doc in ubuntu hirsute.

No description available for python-pil-doc in ubuntu hirsute.

python3-pil: No summary available for python3-pil in ubuntu hirsute.

No description available for python3-pil in ubuntu hirsute.

python3-pil-dbg: No summary available for python3-pil-dbg in ubuntu hirsute.

No description available for python3-pil-dbg in ubuntu hirsute.

python3-pil.imagetk: No summary available for python3-pil.imagetk in ubuntu hirsute.

No description available for python3-pil.imagetk in ubuntu hirsute.

python3-pil.imagetk-dbg: No summary available for python3-pil.imagetk-dbg in ubuntu hirsute.

No description available for python3-pil.imagetk-dbg in ubuntu hirsute.