Publishing details

Changelog

pillow (2.3.0-1ubuntu3.4) trusty-security; urgency=medium

  * SECURITY UPDATE: information disclosure via crafted image
    - debian/patches/CVE-2016-9189.patch: add overflow checks to map.c.
    - CVE-2016-9189
  * SECURITY UPDATE: code execution via crafted image
    - debian/patches/CVE-2016-9190.patch: add size check to
      libImaging/Storage.c, add test to Tests/images/negative_size.ppm,
      Tests/test_file_ppm.py.
    - CVE-2016-9190
  * SECURITY UPDATE: re-enabled CVE-2014-9601 fix
    - debian/patches/pillow-CVE-2014-9601-pre.patch: rename len variables
      as length in PIL/PngImagePlugin.py.
    - debian/patches/pillow-CVE-2014-9601.patch: updated.
    - debian/patches/revert-CVE-201409601.patch: removed
    - CVE-2014-9601

 -- Marc Deslauriers <email address hidden>  Fri, 10 Mar 2017 08:26:41 -0500

Available diffs

Builds

Built packages

Package files