Login
Newsletter
Werbung

Sicherheit: Denial of Service in python-pillow
Aktuelle Meldungen Distributionen
Name: Denial of Service in python-pillow
ID: FEDORA-2014-9540
Distribution: Fedora
Plattformen: Fedora 20
Datum: Mi, 27. August 2014, 08:39
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3589
Applikationen: Pillow

Originalnachricht

Name        : python-pillow
Product : Fedora 20
Version : 2.2.1
Release : 5.fc20
URL : http://python-imaging.github.com/Pillow/
Summary : Python image processing library
Description :
Python image processing library, fork of the Python Imaging Library (PIL)

This library provides extensive file format support, an efficient
internal representation, and powerful image processing capabilities.

There are five subpackages: tk (tk interface), qt (PIL image wrapper for Qt),
sane (scanning devices interface), devel (development) and doc (documentation).

-------------------------------------------------------------------------------
-
Update Information:

Security fix for CVE-2014-3589
-------------------------------------------------------------------------------
-
ChangeLog:

* Sun Aug 17 2014 Sandro Mani <manisandro@gmail.com> - 2.2.1-5
- Fix CVE-2014-3589 (rhbz #1130712)
* Tue Apr 22 2014 Sandro Mani <manisandro@gmail.com> - 2.2.1-4
- Fix CVE-2014-1933 (rhbz #1063660)
* Thu Mar 13 2014 Jakub Dorňák <jdornak@redhat.com> - 2.2.1-3
- python-pillow does not provide python3-imaging
(python3-pillow does)
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #1130711 - CVE-2014-3589 python-pillow: DoS in IcnsImagePlugin
https://bugzilla.redhat.com/show_bug.cgi?id=1130711
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update python-pillow' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung