[ubuntu/wily-updates] pillow 2.9.0-1ubuntu0.2 (Accepted)

Ubuntu Archive Robot cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Tue Sep 27 20:28:11 UTC 2016


pillow (2.9.0-1ubuntu0.2) wily-security; urgency=medium

  * SECURITY UPDATE: buffer overflow in ImagingFliDecode()
    - debian/patches/pillow-CVE-2016-0775.patch: correct memcpy location
    - debian/source/include-binaries: add test image in
      Tests/images/fli_overflow.fli
    - CVE-2016-0775
  * SECURITY UPDATE: buffer overflow in ImagingLibTiffDecode
    - debian/patches/pillow-CVE-2016-0740.patch: correct type of size to
      match that returned by libtiff
    - debian/source/include-binaries: add test image in
      Tests/images/libtiff_segfault.tif
    - CVE-2016-0740
  * SECURITY UPDATE: integer overflow in ImagingResampleHorizontal()
    - debian/patches/pillow-gh#1714.patch: check for integer overflow
  * SECURITY UPDATE: PCD decoder overruns the shuffle buffer
    - debian/patches/pillow-gh#1706.patch: correct size adjustments
    - CVE-2016-2533

Date: 2016-03-12 13:32:23.246318+00:00
Changed-By: Steve Beattie <sbeattie at ubuntu.com>
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/+source/pillow/2.9.0-1ubuntu0.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Wily-changes mailing list