pillow 8.1.2+dfsg-0.1ubuntu1 source package in Ubuntu

Changelog

pillow (8.1.2+dfsg-0.1ubuntu1) impish; urgency=medium

  * SECURITY UPDATE: OOB read in Jpeg2KDecode
    - debian/patches/CVE-2021-25287_8.patch: handle different widths for
      each band in src/libImaging/Jpeg2KDecode.c.
    - CVE-2021-25287
    - CVE-2021-25288
  * SECURITY UPDATE: DOS in PsdImagePlugin
    - debian/patches/CVE-2021-28675.patch: sanity check the number of
      input layers in Tests/test_decompression_bomb.py,
      Tests/test_file_apng.py, Tests/test_file_blp.py,
      Tests/test_file_tiff.py, src/PIL/ImageFile.py,
      src/PIL/PsdImagePlugin.py.
    - CVE-2021-28675
  * SECURITY UPDATE: FLI DOS
    - debian/patches/CVE-2021-28676.patch: check the block advance in
      src/libImaging/FliDecode.c.
    - CVE-2021-28676
  * SECURITY UPDATE: EPS DOS on _open
    - debian/patches/CVE-2021-28677.patch: properly handle line endings in
      src/PIL/EpsImagePlugin.py.
    - CVE-2021-28677
  * SECURITY UPDATE: BLP DOS
    - debian/patches/CVE-2021-28678.patch: check that reads return data in
      src/PIL/BlpImagePlugin.py.
    - CVE-2021-28678

 -- Marc Deslauriers <email address hidden>  Tue, 18 May 2021 07:02:45 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Impish
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
misc
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
pillow_8.1.2+dfsg.orig.tar.xz 35.8 MiB 7fb9b5e9306bfc30990322314cd92b6befd8e6ab9af6ef5bbccca18f938e4e49
pillow_8.1.2+dfsg-0.1ubuntu1.debian.tar.xz 22.4 KiB c55be6a52ef45331feac3dd78e22b7f31c8d71f8b92a97ac204c89fed20f3b1e
pillow_8.1.2+dfsg-0.1ubuntu1.dsc 2.5 KiB bbc326a8addb0195ea4eee93ecc5bf789b2a87e7e0f74bc62644d19943938619

View changes file

Binary packages built by this source

python-pil-doc: No summary available for python-pil-doc in ubuntu impish.

No description available for python-pil-doc in ubuntu impish.

python3-pil: No summary available for python3-pil in ubuntu impish.

No description available for python3-pil in ubuntu impish.

python3-pil-dbg: No summary available for python3-pil-dbg in ubuntu impish.

No description available for python3-pil-dbg in ubuntu impish.

python3-pil.imagetk: No summary available for python3-pil.imagetk in ubuntu impish.

No description available for python3-pil.imagetk in ubuntu impish.

python3-pil.imagetk-dbg: No summary available for python3-pil.imagetk-dbg in ubuntu impish.

No description available for python3-pil.imagetk-dbg in ubuntu impish.