[ubuntu/focal-updates] pillow 7.0.0-4ubuntu0.7 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Tue Dec 13 12:58:19 UTC 2022


pillow (7.0.0-4ubuntu0.7) focal-security; urgency=medium

  * SECURITY UPDATE: arbitrary file deletion
    - debian/patches/CVE-2022-24303.patch: No longer remove temporary images
      manually in src/PIL/ImageShow.py.
    - CVE-2022-24303
  * SECURITY UPDATE: gif decompression bomb issue
    - debian/patches/CVE-2022-45198.patch: Added GIF decompression bomb check
      in src/PIL/GifImagePlugin.py.
    - CVE-2022-45198

Date: 2022-12-12 21:19:09.319222+00:00
Changed-By: Fabian Toepfer <fabian.toepfer at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/pillow/7.0.0-4ubuntu0.7
-------------- next part --------------
Sorry, changesfile not available.


More information about the Focal-changes mailing list