[ubuntu/bionic-security] pillow 5.1.0-1ubuntu0.8 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Mon Oct 24 13:34:54 UTC 2022


pillow (5.1.0-1ubuntu0.8) bionic-security; urgency=medium

  * SECURITY UPDATE: incomplete fix for CVE-2022-22817
    - debian/patches/CVE-2022-22817-2.patch: restrict builtins within
      lambdas for ImageMath.eval in Tests/test_imagemath.py,
      src/PIL/ImageMath.py.
    - CVE-2022-22817

Date: 2022-10-20 17:22:10.012503+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/pillow/5.1.0-1ubuntu0.8
-------------- next part --------------
Sorry, changesfile not available.


More information about the Bionic-changes mailing list