Publishing details

Changelog

pillow (3.1.2-0ubuntu1.6) xenial-security; urgency=medium

  * SECURITY UPDATE: negative-offset memcpy with an invalid size
    - debian/patches/CVE-2021-25290.patch: add extra check to
      libImaging/TiffDecode.c.
    - CVE-2021-25290
  * SECURITY UPDATE: DoS via invalid reported size
    - debian/patches/CVE-2021-2792x.patch: check reported sizes in
      PIL/IcnsImagePlugin.py, PIL/IcoImagePlugin.py.
    - CVE-2021-27922
    - CVE-2021-27923

 -- Marc Deslauriers <email address hidden>  Thu, 11 Mar 2021 07:51:05 -0500

Available diffs

Builds

Built packages

Package files