critical
Security update for python-pillow
SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-1673
This update for python-Pillow fixes the following issues: - Fixed ImagePath.Path array handling (bsc#1194552, CVE-2022-22815, bsc#1194551, CVE-2022-22816) - Use snprintf instead of sprintf (bsc#1188574, CVE-2021-34552) - Fix Memory DOS in Icns, Ico and Blp Image Plugins. (bsc#1183110, CVE-2021-27921, bsc#1183108, CVE-2021-27922, bsc#1183107, CVE-2021-27923) - Fix OOB read in SgiRleDecode.c (bsc#1183102, CVE-2021-25293) - Use more specific regex chars to prevent ReDoS (bsc#1183101, CVE-2021-25292) - Fix negative size read in TiffDecode.c (bsc#1183105, CVE-2021-25290) - Raise ValueError if color specifier is too long (bsc#1190229, CVE-2021-23437) - Incorrect error code checking in TiffDecode.c (bsc#1183103, CVE-2021-25289) - OOB Write in TiffDecode.c (bsc#1180833, CVE-2020-35654)
-
Release DateJun 13 2024
-
ReferencesBugzilla: 1194551, 1180833, 1194552, 1183107, 1183102, 1183101, 1183103, 1183108, 1188574, 1183110, 1183105, 1190229
CVEs: CVE-2021-25292, CVE-2021-23437, CVE-2020-35654, CVE-2021-27923, CVE-2021-25289, CVE-2021-27922, CVE-2021-25293, CVE-2022-22815, CVE-2021-27921, CVE-2021-25290, CVE-2021-34552, CVE-2022-22816 -
Typesecurity
-
Severitycritical
cloud_download Downloads
SUSE Package Hub 15.6 aarch64
-
Packagespython-Pillow
Python Imaging Library (Fork)python3-Pillow7.2.0-150300.3.15.1 lock src
Python Imaging Library (Fork)7.2.0-150300.3.15.1 lock rpm
SUSE Package Hub 15.6 ppc64le
-
Packagespython-Pillow
Python Imaging Library (Fork)python3-Pillow7.2.0-150300.3.15.1 lock src
Python Imaging Library (Fork)7.2.0-150300.3.15.1 lock rpm
SUSE Package Hub 15.6 x86_64
-
Packagespython-Pillow
Python Imaging Library (Fork)python3-Pillow7.2.0-150300.3.15.1 lock src
Python Imaging Library (Fork)7.2.0-150300.3.15.1 lock rpm
SUSE Package Hub 15.6 s390x
-
Packagespython-Pillow
Python Imaging Library (Fork)python3-Pillow7.2.0-150300.3.15.1 lock src
Python Imaging Library (Fork)7.2.0-150300.3.15.1 lock rpm