[ubuntu/focal-security] pillow 7.0.0-4ubuntu0.7 (Accepted)
Fabian Toepfer
fabian.toepfer at canonical.com
Tue Dec 13 12:18:30 UTC 2022
pillow (7.0.0-4ubuntu0.7) focal-security; urgency=medium
* SECURITY UPDATE: arbitrary file deletion
- debian/patches/CVE-2022-24303.patch: No longer remove temporary images
manually in src/PIL/ImageShow.py.
- CVE-2022-24303
* SECURITY UPDATE: gif decompression bomb issue
- debian/patches/CVE-2022-45198.patch: Added GIF decompression bomb check
in src/PIL/GifImagePlugin.py.
- CVE-2022-45198
Date: 2022-12-12 21:19:09.319222+00:00
Changed-By: Fabian Toepfer <fabian.toepfer at canonical.com>
https://launchpad.net/ubuntu/+source/pillow/7.0.0-4ubuntu0.7
-------------- next part --------------
Sorry, changesfile not available.
More information about the Focal-changes
mailing list