Incoming details.
* CVE-2019-19911: Prevent a denial-of-service vulnerability caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. * CVE-2020-5312: PCX "P mode" buffer overflow. * CVE-2020-5313: FLI buffer overflow.
FWICS they're all fixed in 6.2.2.
x86 stable
sparc stable
arm stable
amd64 stable
ppc64 stable
ppc stable
arm64 stable
~hppa is fine
Resetting sanity check; keywords are not fully specified and arches are not CC-ed.
Thanks arches. @maintainer(s), please cleanup!
CVE-2020-5311 (https://nvd.nist.gov/vuln/detail/CVE-2020-5311): libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow. CVE-2020-5310 (https://nvd.nist.gov/vuln/detail/CVE-2020-5310): libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=815387495f790a66b5fbf74f014349535fe4bbbc commit 815387495f790a66b5fbf74f014349535fe4bbbc Author: Aaron Bauman <bman@gentoo.org> AuthorDate: 2020-05-04 01:21:39 +0000 Commit: Aaron Bauman <bman@gentoo.org> CommitDate: 2020-05-04 01:22:13 +0000 dev-python/pillow: drop vulnerable Bug: https://bugs.gentoo.org/706202 Signed-off-by: Aaron Bauman <bman@gentoo.org> dev-python/pillow/Manifest | 1 - dev-python/pillow/pillow-6.2.1.ebuild | 98 ----------------------------------- 2 files changed, 99 deletions(-)