Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

pillow: patch or security update to 6.2.0 #2032

Closed
4 tasks done
KexyBiscuit opened this issue Oct 8, 2019 · 2 comments
Closed
4 tasks done

pillow: patch or security update to 6.2.0 #2032

KexyBiscuit opened this issue Oct 8, 2019 · 2 comments
Assignees
Labels
aosa-pending Pending AOSA (AOSC OS Security Advisory) assignment security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade

Comments

@KexyBiscuit
Copy link
Member

KexyBiscuit commented Oct 8, 2019

CVE IDs: CVE-2019-16865

Other security advisory IDs: N/A

Descriptions: An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

Patches: python-pillow/Pillow#4101, python-pillow/Pillow#4102, python-pillow/Pillow#4103, python-pillow/Pillow#4104

PoC(s): N/A

Architectural progress:

  • AMD64 amd64
  • AArch64 arm64
  • ARMv7 armel
  • PowerPC 64-bit BE ppc64
@KexyBiscuit KexyBiscuit added upgrade Topic/issue involves a package upgrade security Topic/issue involves a security issue/fixed to-testing labels Oct 8, 2019
@KexyBiscuit KexyBiscuit added this to the Fall 2019 milestone Oct 8, 2019
@KexyBiscuit KexyBiscuit self-assigned this Oct 8, 2019
@MingcongBai
Copy link
Member

All done. @l2dy Please assign an AOSA.

@MingcongBai MingcongBai added the aosa-pending Pending AOSA (AOSC OS Security Advisory) assignment label Apr 20, 2020
@l2dy
Copy link
Member

l2dy commented Apr 21, 2020

Use AOSA-2020-0071.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
aosa-pending Pending AOSA (AOSC OS Security Advisory) assignment security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade
Projects
None yet
Development

No branches or pull requests

3 participants