[ubuntu/focal-updates] pillow 7.0.0-4ubuntu0.7 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Tue Dec 13 12:58:19 UTC 2022
pillow (7.0.0-4ubuntu0.7) focal-security; urgency=medium
* SECURITY UPDATE: arbitrary file deletion
- debian/patches/CVE-2022-24303.patch: No longer remove temporary images
manually in src/PIL/ImageShow.py.
- CVE-2022-24303
* SECURITY UPDATE: gif decompression bomb issue
- debian/patches/CVE-2022-45198.patch: Added GIF decompression bomb check
in src/PIL/GifImagePlugin.py.
- CVE-2022-45198
Date: 2022-12-12 21:19:09.319222+00:00
Changed-By: Fabian Toepfer <fabian.toepfer at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/pillow/7.0.0-4ubuntu0.7
-------------- next part --------------
Sorry, changesfile not available.
More information about the Focal-changes
mailing list