Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in python2-pillow
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in python2-pillow
ID: FEDORA-2021-0ece308612
Distribution: Fedora
Plattformen: Fedora 32
Datum: Mo, 15. März 2021, 07:36
Referenzen: https://bugzilla.redhat.com/show_bug.cgi?id=1936047
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27923
https://bugzilla.redhat.com/show_bug.cgi?id=1933899
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25291
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35654
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25292
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25290
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25289
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27921
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25293
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27922
Applikationen: Pillow

Originalnachricht

-------------------------------------------------------------------------------
-
Fedora Update Notification
FEDORA-2021-0ece308612
2021-03-15 01:05:35.340646
-------------------------------------------------------------------------------
-

Name : python2-pillow
Product : Fedora 32
Version : 6.2.2
Release : 5.fc32
URL : http://python-pillow.github.io/
Summary : Python image processing library
Description :
Python image processing library, fork of the Python Imaging Library (PIL)

This library provides extensive file format support, an efficient
internal representation, and powerful image processing capabilities.

This is a minimal compatibility package for https://pagure.io/fesco/issue/2266

-------------------------------------------------------------------------------
-
Update Information:

This update fixes CVE-2021-27921, CVE-2021-27922 and CVE-2021-27923. ----
Backport fixes for CVE-2021-25289, CVE-2021-25290, CVE-2021-25291,
CVE-2021-25292, CVE-2021-25293
-------------------------------------------------------------------------------
-
ChangeLog:

* Sat Mar 6 2021 Sandro Mani <manisandro@gmail.com> - 6.2.2-5
- Backport patch for CVE-2021-2792{1,2,3}
* Fri Mar 5 2021 Sandro Mani <manisandro@gmail.com> - 6.2.2-4
- Backport fixes for CVE-2020-35653, CVE-2020-35654, CVE-2020-35655
- Backport fixes for CVE-2021-25289, CVE-2021-25290, CVE-2021-25291,
CVE-2021-25292, CVE-2021-25293
* Wed Jul 29 2020 Fedora Release Engineering <releng@fedoraproject.org> -
6.2.2-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #1933899 - python-pillow-8.1.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1933899
[ 2 ] Bug #1934681 - CVE-2021-25289 python-pillow: insufficent fix for
CVE-2020-35654 due to incorrect error checking in TiffDecode.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1934681
[ 3 ] Bug #1934682 - CVE-2021-25289 python2-pillow: python-pillow:
insufficent fix for CVE-2020-35654 due to incorrect error checking in TiffDecode.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1934682
[ 4 ] Bug #1934683 - CVE-2021-25289 mingw-python-pillow: python-pillow:
insufficent fix for CVE-2020-35654 due to incorrect error checking in TiffDecode.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1934683
[ 5 ] Bug #1934686 - CVE-2021-25290 python-pillow: negative-offset memcpy
with an invalid size in TiffDecode.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1934686
[ 6 ] Bug #1934687 - CVE-2021-25290 python2-pillow: python-pillow:
negative-offset memcpy with an invalid size in TiffDecode.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1934687
[ 7 ] Bug #1934688 - CVE-2021-25290 mingw-python-pillow: python-pillow:
negative-offset memcpy with an invalid size in TiffDecode.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1934688
[ 8 ] Bug #1934693 - CVE-2021-25291 python-pillow: out-of-bounds read in
TiffReadRGBATile in TiffDecode.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1934693
[ 9 ] Bug #1934694 - CVE-2021-25291 python2-pillow: python-pillow:
out-of-bounds read in TiffReadRGBATile in TiffDecode.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1934694
[ 10 ] Bug #1934695 - CVE-2021-25291 mingw-python-pillow: python-pillow:
out-of-bounds read in TiffReadRGBATile in TiffDecode.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1934695
[ 11 ] Bug #1934700 - CVE-2021-25292 python-pillow: backtracking regex in PDF
parser could be used as a DOS attack [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1934700
[ 12 ] Bug #1934701 - CVE-2021-25292 python2-pillow: python-pillow:
backtracking regex in PDF parser could be used as a DOS attack [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1934701
[ 13 ] Bug #1934702 - CVE-2021-25292 mingw-python-pillow: python-pillow:
backtracking regex in PDF parser could be used as a DOS attack [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1934702
[ 14 ] Bug #1934706 - CVE-2021-25293 python-pillow: out-of-bounds read in
SGIRleDecode.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1934706
[ 15 ] Bug #1934707 - CVE-2021-25293 python2-pillow: python-pillow:
out-of-bounds read in SGIRleDecode.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1934707
[ 16 ] Bug #1934708 - CVE-2021-25293 mingw-python-pillow: python-pillow:
out-of-bounds read in SGIRleDecode.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1934708
[ 17 ] Bug #1935385 - CVE-2021-27921 python-pillow: reported size of a
contained image is not properly checked for a BLP container [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1935385
[ 18 ] Bug #1935386 - CVE-2021-27921 python2-pillow: python-pillow: reported
size of a contained image is not properly checked for a BLP container [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1935386
[ 19 ] Bug #1935388 - CVE-2021-27921 mingw-python-pillow: python-pillow:
reported size of a contained image is not properly checked for a BLP container [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1935388
[ 20 ] Bug #1935397 - CVE-2021-27922 python-pillow: reported size of a
contained image is not properly checked for an ICNS container [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1935397
[ 21 ] Bug #1935398 - CVE-2021-27922 python2-pillow: python-pillow: reported
size of a contained image is not properly checked for an ICNS container [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1935398
[ 22 ] Bug #1935399 - CVE-2021-27922 mingw-python-pillow: python-pillow:
reported size of a contained image is not properly checked for an ICNS container [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1935399
[ 23 ] Bug #1935402 - CVE-2021-27923 python-pillow: reported size of a
contained image is not properly checked for an ICO container [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1935402
[ 24 ] Bug #1935403 - CVE-2021-27923 python2-pillow: python-pillow: reported
size of a contained image is not properly checked for an ICO container [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1935403
[ 25 ] Bug #1935405 - CVE-2021-27923 mingw-python-pillow: python-pillow:
reported size of a contained image is not properly checked for an ICO container [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1935405
[ 26 ] Bug #1936047 - python-pillow-8.1.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1936047
-------------------------------------------------------------------------------
-

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2021-0ece308612' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung