DSA-4631-1

Source
https://storage.googleapis.com/debian-osv/dsa-osv/DSA-4631-1.json
Aliases
Published
2020-02-21T00:00:00Z
Modified
2022-08-10T07:15:20.836484Z
Details

Multiple security issues were discovered in Pillow, a Python imaging library, which could result in denial of service and potentially the execution of arbitrary code if malformed PCX, FLI, SGI or TIFF images are processed.

For the oldstable distribution (stretch), these problems have been fixed in version 4.0.0-4+deb9u1.

For the stable distribution (buster), these problems have been fixed in version 5.4.1-2+deb10u1.

We recommend that you upgrade your pillow packages.

For the detailed security status of pillow please refer to its security tracker page at: \ https://security-tracker.debian.org/tracker/pillow

References

Affected packages

Debian:9 / pillow

pillow

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0
Fixed
4.0.0-4+deb9u1

Affected versions

4.*

4.0.0-4

Debian:10 / pillow

pillow

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0
Fixed
5.4.1-2+deb10u1

Affected versions

5.*

5.4.1-2